Junglewise Threat Intelligence

CVE-2026-12438: Google Chrome WebView sandbox escape on Android

CVE-2026-12438 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Google Chrome for Android, Google WebView. Vendors: Google.

Executive brief

A security vulnerability exists in the WebView component of Google Chrome on Android, which is used by many mobile apps to display web content. An attacker who has already partially compromised the browser's internal processes could use a specially crafted webpage to break out of the security sandbox. If successful, this could allow the attacker to gain broader access to the underlying Android operating system and user data.

Technical details

This vulnerability is classified as a protection mechanism failure (CWE-693) within the WebView component of Google Chrome for Android. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions. By enticing a user to visit a malicious HTML page, the attacker can escalate their privileges to escape the renderer sandbox and interact with the broader system. The vulnerability was addressed in version 149.0.7827.155. While the attack requires a high degree of complexity and an initial compromise, the impact is rated as critical due to the potential for full system compromise.

Affected products

  • Google Chrome for Android prior to 149.0.7827.155
  • Google WebView prior to 149.0.7827.155

Timeline

  • 2026-05-27: other: Reported to Google by internal researchers
  • 2026-06-16: patched: Stable channel update released for desktop and Android versions
  • 2026-06-17: advisory: NVD publication date

References

Related threats