Description
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Inappropriate implementation in the Android WebView component of Google Chrome allowed a remote attacker to construct a crafted HTML page that could read cross‑origin data, thereby exposing sensitive information to an unauthorized party. This vulnerability permits the attacker to gain unintended access to data from other origins, compromising the confidentiality of those resources. The weakness is classified as a medium‑severity flaw according to Chromium’s internal severity assessment.

Affected Systems

Google Chrome for Android versions prior to 149.0.7827.53 are affected. The flaw exists specifically in the WebView functionality used by Chrome, and therefore any Android device running one of the listed versions may be vulnerable if it hosts or allows execution of the malicious HTML page.

Risk and Exploitability

The vulnerability is exploitable remotely through a crafted web page, implying that an attacker needs only to entice a user to visit or load the page. With no EPSS score available, the current exploit probability cannot be quantified, however the lack of a KEV listing suggests no widespread exploitation has been reported to date. The medium severity rating indicates the impact is significant but not catastrophic, and the attack is feasible up to the availability of a patch.

Generated by OpenCVE AI on June 5, 2026 at 02:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 149.0.7827.53 or later
  • Enable automatic updates for Chrome to receive security patches promptly
  • Review Android applications that embed WebView components and verify they use the latest, secured WebView version

Generated by OpenCVE AI on June 5, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leakage via Insecure WebView in Chrome for Android
Weaknesses CWE-200

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:04:55.218Z

Reserved: 2026-06-04T17:06:49.440Z

Link: CVE-2026-11097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:17:15.180

Modified: 2026-06-04T23:17:15.180

Link: CVE-2026-11097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T02:30:29Z

Weaknesses