Description
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-24
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the WebView component of Google Chrome on Android. A crafted HTML page can trigger an invalid memory reference, allowing a local attacker to execute arbitrary code inside Chrome’s sandbox process. The vulnerability is classified as high severity by Chromium security and is identified as CWE‑416, a consequential memory misuse that can lead to arbitrary code execution.

Affected Systems

The flaw affects Google Chrome on Android running versions prior to 149.0.7827.197. No specific branch or release outside of Android is known to be impacted. Users of the latest desktop Chrome releases are not affected by this particular bug.

Risk and Exploitability

Because the vulnerability requires a local attacker with access to render a malicious HTML page, the attack vector is local. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploits at this time. However, the high CVSS score for the Chromium security severity suggests that if an attacker gains the local execution capability, they could escape the sandbox and compromise the host system. The patch is available only in newer Chrome releases for Android.

Generated by OpenCVE AI on June 24, 2026 at 20:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to the latest patched version that includes WebView fixes (at least 149.0.7827.198 or higher).
  • If an immediate update is not possible, configure Chrome to disallow loading of local files into WebView (disable file:// or data: schemes) to reduce the attack surface.
  • Continuously monitor official Google Chrome release notes and security advisories for ongoing patches and workarounds, and apply them promptly.

Generated by OpenCVE AI on June 24, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome WebView Enabling Local Code Execution

Wed, 24 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 19:15:00 +0000

Type Values Removed Values Added
Description Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-24T19:35:26.287Z

Reserved: 2026-06-23T17:14:12.890Z

Link: CVE-2026-13037

cve-icon Vulnrichment

Updated: 2026-06-24T19:21:09.253Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:30:04Z

Weaknesses