Junglewise Threat Intelligence

CVE-2026-79273: Google Chrome WebView incorrect reference resolution bypass

CVE-2026-79273 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebView component on Android contains a flaw in how it resolves references that allows attackers to bypass the browser's same-origin security policy. By crafting a malicious HTML page, an attacker could potentially access or manipulate content across different websites when users visit the attacker's page, compromising the fundamental security isolation between websites.

Technical details

The vulnerability exists in the WebView component of Google Chrome on Android versions prior to 152.0.7977.65 and stems from incorrect reference resolution logic. An attacker can craft a specially designed HTML page that exploits this flaw to bypass web origin policy, the mechanism that prevents scripts and resources from one website from accessing data on another website. The attack requires user interaction (visiting a malicious webpage) and is network-reachable. The vulnerability allows potential elevation of privileges or unauthorized data access. The fix is available in Chrome 152.0.7977.65 and later for Android.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats