Executive brief
Google Chrome's WebView component on Android contains a vulnerability that allows an attacker with access to the browser's renderer process to escape the sandbox and execute arbitrary code on the device. This could enable an attacker to compromise sensitive user data, install malware, or take complete control of the affected device's browser functionality.
Technical details
The vulnerability is an externally controlled reference flaw in WebView on Android that permits sandbox escape. An attacker who has already compromised the renderer process (via another vulnerability or attack) can craft a malicious HTML page to exploit this reference issue, leading to arbitrary code execution outside the sandbox boundary. The attack requires prior renderer compromise as a precondition. Google patched this issue in Chrome 152.0.7977.65 and later versions; users running versions prior to 152.0.7977.65 on Android are affected.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65