Executive brief
Google Chrome for Android contains a security vulnerability in its WebView component, which is used by many apps to display web content. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the device. While the impact is limited by the browser's security sandbox, it could still lead to data theft or further compromise of the application using WebView.
Technical details
A use-after-free (UAF) vulnerability exists in the WebView component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing a remote, unauthenticated attacker to achieve arbitrary code execution within the renderer process sandbox. Exploitation requires the victim to navigate to a malicious web page. The vulnerability is addressed in version 150.0.7871.47 and later. The Chromium project classifies this as Medium severity.
Affected products
- Google Chrome for Android Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched