Junglewise Threat Intelligence

CVE-2026-17722: Google Chrome WebView object lifecycle sandbox escape on Android

CVE-2026-17722 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the WebView component of Google Chrome for Android, which is used by many apps to display web content. If an attacker has already compromised the browser's content-rendering process, they could use this flaw to break out of the security sandbox. This could allow them to gain broader access to the underlying Android device and its data.

Technical details

This vulnerability is classified as an object lifecycle issue within the WebView component of Google Chrome for Android. The flaw resides in how the browser manages the state and duration of internal objects. An attacker who has already achieved code execution within a compromised renderer process can exploit this issue by serving a specially crafted HTML page. Successful exploitation allows the attacker to perform a sandbox escape, bypassing the security boundaries that normally isolate the browser process from the rest of the operating system. The issue was addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats