Junglewise Threat Intelligence

CVE-2026-13964: Google Chrome WebView navigation restriction bypass on Android

CVE-2026-13964 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebView component on Android could allow a malicious website to bypass intended navigation restrictions. WebView is the technology that allows Android apps to display web content directly within the application. If exploited, an attacker could force the browser to navigate to unauthorized pages or bypass security boundaries designed to keep web sessions isolated.

Technical details

An insufficient policy enforcement vulnerability exists in the WebView component of Google Chrome for Android. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. This bypass occurs because the component fails to strictly enforce security policies governing how and where the browser can navigate. An attacker could leverage this to redirect users to unintended locations or circumvent security controls that rely on navigation constraints. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats