Junglewise Threat Intelligence

CVE-2026-17915: Google Chrome WebView UI spoofing via crafted HTML page

CVE-2026-17915 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome WebView. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome WebView component on Android could allow a malicious website to spoof user interface elements. This means an attacker could trick users into performing unintended actions or disclosing information by displaying fake prompts or overlays that appear to be legitimate parts of the application or system. The issue is resolved by updating to the latest version of Chrome on Android.

Technical details

An inappropriate implementation vulnerability exists in the WebView component of Google Chrome for Android prior to version 151.0.7922.72. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, which can be used to facilitate phishing or other social engineering attacks by misrepresenting the application's interface. The vulnerability is classified by Chromium as Low severity and is addressed in the stable channel update 151.0.7922.72.

Affected products

  • Google Chrome WebView prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for Android/Desktop
  • 2026-07-30: disclosed: NVD publication date

References

Related threats