Junglewise Threat Intelligence

CVE-2026-17767: Google Chrome WebView insufficient input validation in Android

CVE-2026-17767 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome WebView. Vendors: Google.

Executive brief

A security vulnerability has been identified in the WebView component of Google Chrome for Android, which is used by many mobile apps to display web content. This flaw could allow a malicious website to access data from other websites that the user has open, potentially leading to the exposure of sensitive personal or account information. Users should update their Chrome browser and Android System WebView via the Google Play Store to the latest version to remain protected.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebView component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker who has already achieved a compromise of the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can bypass cross-origin boundaries to leak sensitive data from other origins. This vulnerability is addressed in version 151.0.7922.72 and later.

Affected products

  • Google Chrome WebView prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats