Executive brief
A vulnerability in the WebView component of Google Chrome for Android could allow a malicious website to escape the browser's security sandbox. WebView is a system component that allows Android apps to display web content. If exploited, an attacker who has already gained limited control over the browser's rendering process could potentially gain broader access to the underlying device or user data.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the WebView component of Google Chrome for Android. The flaw exists because the application does not sufficiently validate untrusted input, which can be leveraged by a remote attacker. To exploit this, an attacker must first compromise the renderer process, typically through a separate vulnerability. Once the renderer is compromised, the attacker can use a specially crafted HTML page to trigger the input validation failure and perform a sandbox escape. This would allow the attacker to bypass the security boundaries intended to isolate web content from the rest of the operating system. Google has addressed this issue in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Chrome Stable Channel update published
- 2026-07-30: disclosed: NVD publication date