Junglewise Threat Intelligence

CVE-2026-12448: Google Chrome WebView privilege escalation on Android

CVE-2026-12448 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Google Chrome WebView, Google WebView. Vendors: Google.

Executive brief

Google Chrome's WebView, a component used by Android apps to display web content, contains a security flaw that could allow a remote attacker to gain elevated privileges on a device. By tricking a user into visiting a specially crafted website, an attacker could potentially bypass security restrictions to access sensitive data or perform unauthorized actions. This issue affects Android users running older versions of the Chrome browser and WebView component.

Technical details

A privilege escalation vulnerability exists in the WebView component of Google Chrome for Android due to an inappropriate implementation of security controls. The flaw, classified under CWE-269 (Improper Privilege Management), can be triggered by a remote attacker who convinces a user to load a malicious HTML page. Successful exploitation allows the attacker to escalate privileges within the context of the application using WebView. The vulnerability was addressed in version 149.0.7827.155; users are advised to update their Chrome and WebView components to the latest available version.

Affected products

  • Google Chrome WebView prior to 149.0.7827.155

Timeline

  • 2026-05-15: disclosed: Reported to Chromium project
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD/CVE published

References

Related threats