Description
Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An Android WebView component in Google Chrome suffered from insufficient validation of untrusted input, allowing an attacker to craft a malicious HTML page that could bypass the same origin policy. This flaw lets a compromised renderer process read data from or interact with websites that belong to a different domain, undermining data confidentiality and potentially enabling further malicious actions.

Affected Systems

All Android devices running Google Chrome versions older than 150.0.7871.47 are affected. The vulnerability was fixed in the stable channel update released in June 2026, which includes version 150.0.7871.47 and later. Users of any earlier releases must ensure they migrate to the patched build.

Risk and Exploitability

The vulnerability is catalogued as medium severity by Chromium. Exploitation requires a compromise of the renderer process, which is non‑trivial, and no current exploit code has been confirmed in the wild. EPSS data is not available and the flaw is not listed in the CISA KEV catalog, indicating a lower but still present risk. However, operator awareness and rapid patching remain important to prevent potential exploitation.

Generated by OpenCVE AI on July 1, 2026 at 02:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 150.0.7871.47 or later
  • Ensure the Android operating system is updated to the latest stable release to receive all security patches
  • If using WebView in custom applications, restrict the content loaded to known safe origins and disable JavaScript or other vulnerable features for untrusted content

Generated by OpenCVE AI on July 1, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Same Origin Policy Bypass via Untrusted Input in WebView

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-30T22:38:23.269Z

Reserved: 2026-06-29T23:03:53.357Z

Link: CVE-2026-13924

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T03:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation