Description
Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-04
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the WebView component of Google Chrome on Android allows a remote attacker who has already compromised the renderer process to construct a specially crafted HTML page that can potentially escape the browser sandbox, thereby gaining elevated privileges. This flaw could enable the attacker to execute arbitrary code outside the confined environment of the renderer, impacting the confidentiality, integrity, and availability of the underlying Android system.

Affected Systems

Google Chrome on Android devices with versions older than 149.0.7827.53 are affected. These releases include the buggy WebView implementation that permits a malicious HTML page to attempt a sandbox escape.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6, indicating critical severity. The EPSS score is below 1%, signifying a low predicted exploitation probability, and the issue is not listed in the CISA KEV catalog. The likely attack vector requires a remote attacker to first compromise the renderer process; once that is achieved, a crafted HTML page can trigger a sandbox escape. Given the high severity but low exploitation likelihood, the risk remains elevated and warrants prompt remediation.

Generated by OpenCVE AI on June 7, 2026 at 17:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to version 149.0.7827.53 or later
  • Ensure the device’s operating system and Chrome browser are kept current with the latest security patches
  • Restrict or sandbox untrusted HTML content from affecting the renderer by disabling local file access and other privileged APIs when possible

Generated by OpenCVE AI on June 7, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6325-1 chromium security update
History

Mon, 08 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Sun, 07 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Sun, 07 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape in Chrome WebView via Crafted HTML chromium-browser: Inappropriate implementation in WebView
Weaknesses CWE-501
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 05 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-250
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape in Chrome WebView via Crafted HTML
Weaknesses CWE-269

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T17:18:59.333Z

Reserved: 2026-06-04T17:10:35.873Z

Link: CVE-2026-11167

cve-icon Vulnrichment

Updated: 2026-06-05T17:17:59.885Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-04T23:17:23.417

Modified: 2026-06-08T14:22:35.047

Link: CVE-2026-11167

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-11167 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T17:30:04Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges

  • CWE-501

    Trust Boundary Violation