Junglewise Threat Intelligence

CVE-2026-9888: Google Chrome WebView use after free sandbox escape

CVE-2026-9888 · Severity: info · Published 2026-05-28

Technologies: Google Chrome for Android, Google WebView. Vendors: Google.

Executive brief

A critical security vulnerability exists in Google Chrome for Android and the WebView component, which is used by many Android apps to display web content. An attacker who has already partially compromised the browser's internal processes could use a specially crafted website to break out of the security sandbox. This could allow the attacker to gain broader access to the device, potentially compromising user data or system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the WebView component of Google Chrome for Android prior to version 148.0.7778.216. The flaw is categorized under CWE-416 and occurs when the application continues to use a pointer after it has been freed. To exploit this, a remote attacker must first compromise the renderer process. Once achieved, the attacker can leverage a crafted HTML page to trigger the UAF condition and potentially perform a sandbox escape. This would allow the attacker to execute code outside of the restricted browser environment. Google has addressed this in the stable channel update for Android.

Affected products

  • Google Chrome for Android Prior to 148.0.7778.216
  • Google WebView Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop/Android versions.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats