Junglewise Threat Intelligence

CVE-2026-79256: Google Chrome externally controlled reference in WebView on Android

CVE-2026-79256 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebView component on Android contains a vulnerability that allows an attacker with access to the browser's renderer process to escape the sandbox and execute arbitrary code on the device. This could enable an attacker to compromise sensitive user data, install malware, or take complete control of the affected device's browser functionality.

Technical details

The vulnerability is an externally controlled reference flaw in WebView on Android that permits sandbox escape. An attacker who has already compromised the renderer process (via another vulnerability or attack) can craft a malicious HTML page to exploit this reference issue, leading to arbitrary code execution outside the sandbox boundary. The attack requires prior renderer compromise as a precondition. Google patched this issue in Chrome 152.0.7977.65 and later versions; users running versions prior to 152.0.7977.65 on Android are affected.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats