Junglewise Threat Intelligence

CVE-2026-13037: Google Chrome for Android use after free in WebView

CVE-2026-13037 · Severity: info · Published 2026-06-24

Technologies: Google Chrome for Android. Vendors: Google.

Executive brief

A vulnerability in Google Chrome and WebView on Android could allow a malicious website to execute unauthorized code on a user's device. While the attack is limited to a restricted 'sandbox' environment, it represents a significant security risk for users browsing the web or using apps that display web content. Users should update their Chrome browser and Android System WebView to the latest version to remain protected.

Technical details

A use-after-free (UAF) vulnerability exists in the WebView component of Google Chrome on Android (CWE-416). The flaw is triggered when the application attempts to access memory that has already been freed, which can be induced by a specially crafted HTML page. A remote attacker can exploit this to execute arbitrary code within the context of the browser's sandbox. The vulnerability was addressed in version 149.0.7827.197. While the NVD description mentions a 'local' attacker, the primary vector for crafted HTML pages in a browser context is typically remote/network-based.

Affected products

  • Google Chrome for Android prior to 149.0.7827.197
  • Google Android WebView prior to 149.0.7827.197

Timeline

  • 2026-06-14: other: Reported to Chrome by Google researchers
  • 2026-06-23: patched: Stable channel update released
  • 2026-06-24: disclosed: CVE published

References

Related threats