Executive brief
A vulnerability exists in the WebView component of Google Chrome on Android, which is used by many apps to display web content. An attacker could use a specially crafted website to break out of the browser's security restrictions (the sandbox). This could allow unauthorized access to data or functions on the mobile device that are normally protected.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebView component of Google Chrome for Android. The flaw allows a remote attacker to bypass sandbox restrictions by enticing a user to visit a malicious or compromised HTML page. Successful exploitation could lead to a sandbox escape, potentially allowing the attacker to execute code or access data outside of the isolated browser environment. The vulnerability is addressed in version 151.0.7922.72 and later.
Affected products
- Google Chrome for Android prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Google released the stable channel update addressing the issue.
- 2026-07-30: disclosed: NVD published the CVE record.