Executive brief
A security issue in Google Chrome on Android could allow a malicious website to bypass standard security boundaries. This component, known as WebView, is used by many Android apps to display web content. If exploited, an attacker could potentially access data from other websites or interfere with the user's browsing session, though this requires the attacker to have already partially compromised the browser's internal processing.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebView component of Google Chrome for Android. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP), which is the fundamental security mechanism that prevents websites from attacking each other. To successfully exploit this, an attacker must first compromise the renderer process. Once achieved, they can use a specially crafted HTML page to access data across origins. The vulnerability is addressed in version 150.0.7871.47.
Affected products
- Google Chrome for Android prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47