Technology · Google
Google Chrome for Android vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in Google Chrome for Android: 0 in the last 7 days and 3 in the last 90 days, 2 of them critical and 2 exploited in the wild. The most recent, CVE-2026-17741, was published on 30 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 2
- Exploited in the wild
- 2
About Google Chrome for Android
The mobile version of the Google Chrome web browser developed for the Android operating system.
Latest Google Chrome for Android vulnerabilities
- CVE-2026-17741: Google Chrome WebView sandbox escape via improper input validationinfoCVSS 6.5
- CVE-2026-13924: Google Chrome WebView Same Origin Policy bypassinfoCVSS 4.3
- CVE-2026-13870: Google Chrome WebView use after free in AndroidinfoCVSS 6.5
- CVE-2026-13037: Google Chrome for Android use after free in WebViewinfo
- CVE-2026-12438: Google Chrome WebView sandbox escape on AndroidhighCVSS 8.3EPSS 0.3%
- CVE-2026-11297: Google Chrome for Android navigation bypass in Reader ModeinfoCVSS 2
- CVE-2026-11291: Google Chrome for Android SOP bypass in Android Autofillinfo
- CVE-2026-11247: Google Chrome for Android cross-origin data leak in CustomTabsinfoCVSS 3.3
- CVE-2026-11215: Google Chrome for Android domain spoofing in CronetinfoCVSS 4.3
- CVE-2026-11175: Google Chrome for Android UI spoofing in MessagesinfoCVSS 4.3
- CVE-2026-11167: Google Chrome for Android sandbox escape in WebViewinfo
- CVE-2026-11163: Google Chrome for Android use after free in MessagesinfoCVSS 6.5
- CVE-2026-11097: Google Chrome WebView cross-origin data leak on AndroidinfoCVSS 4.3
- CVE-2026-11035: Google Chrome for Android privilege escalation in Custom TabsinfoCVSS 0
- CVE-2026-9892: Google Chrome Skia sandbox escape on AndroidinfoCVSS 9.8
- CVE-2026-9888: Google Chrome WebView use after free sandbox escapeinfo
- CVE-2026-8583: Google Chrome for Android insufficient policy enforcement in WebXRmediumCVSS 5.3EPSS 0.1%
- CVE-2026-8572: Google Chrome insufficient policy enforcement in NetworklowCVSS 3.1EPSS 0.0%
- CVE-2017-5070: Google Chromium V8 Type Confusion Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2017-5030: Google Chromium V8 Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2016-5209: Google Chrome bad casting in Blink bitmap manipulationhighCVSS 8.8
Most severe Google Chrome for Android vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2017-5030: Google Chromium V8 Memory Corruption Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2017-5070: Google Chromium V8 Type Confusion Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2016-5209: Google Chrome bad casting in Blink bitmap manipulationhighCVSS 8.8
- CVE-2026-12438: Google Chrome WebView sandbox escape on AndroidhighCVSS 8.3EPSS 0.3%
- CVE-2026-8583: Google Chrome for Android insufficient policy enforcement in WebXRmediumCVSS 5.3EPSS 0.1%
- CVE-2026-8572: Google Chrome insufficient policy enforcement in NetworklowCVSS 3.1EPSS 0.0%
- CVE-2026-9892: Google Chrome Skia sandbox escape on AndroidinfoCVSS 9.8
- CVE-2026-17741: Google Chrome WebView sandbox escape via improper input validationinfoCVSS 6.5
- CVE-2026-13870: Google Chrome WebView use after free in AndroidinfoCVSS 6.5
- CVE-2026-11163: Google Chrome for Android use after free in MessagesinfoCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/chrome-for-android.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Google Chrome for Android vulnerabilities", https://junglewise.ai/threats/technologies/chrome-for-android, 26 September 2026.