Executive brief
A vulnerability in the Android WebView component of Google Chrome could allow a malicious website to bypass intended navigation restrictions. WebView is the technology that allows Android apps to display web content directly within the application. If exploited, an attacker could potentially direct users to unauthorized or malicious web pages that should have been blocked by the app's security policies.
Technical details
An insufficient policy enforcement vulnerability exists in the WebView component of Google Chrome for Android. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. This bypass occurs because the component fails to strictly enforce security policies governing how and where the browser can navigate. An attacker can leverage this to force the WebView to load content from restricted origins or bypass intent-based filters. The issue is resolved in version 151.0.7922.72.
Affected products
- Google Chrome WebView prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed