Executive brief
Google Chrome's WebView component on Android contains a missing authorization flaw that allows remote attackers to bypass system access restrictions through social engineering and crafted network traffic. This vulnerability could enable unauthorized access to protected resources or functionality on affected devices.
Technical details
The vulnerability is a missing authorization issue in WebView, a component of Google Chrome on Android. An attacker can bypass system access restrictions by leveraging social engineering tactics combined with specially crafted network traffic. The flaw affects Chrome versions prior to 153.0.8010.36. While the Chromium team assessed this as Medium severity, the attack vector is network-based and exploits improper authorization controls, allowing an attacker to circumvent intended access controls without requiring special privileges.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released