Impact
CVE‑2026‑7342 is a use‑after‑free vulnerability in the WebView component of Google Chrome on Android. The flaw allows a remote attacker to craft a malicious HTML page that triggers the freed memory to be accessed again, resulting in execution of arbitrary code inside the sandbox. The vulnerability is classified as high severity.
Affected Systems
The affected product is Google Chrome WebView on Android, specifically versions earlier than 147.0.7727.138. Devices running these versions can be impacted by a maliciously crafted HTML page delivered over the network.
Risk and Exploitability
The attack vector is remote, requiring an attacker to deliver a specially formed HTML page to a vulnerable device. While exploitation has not been confirmed in the wild, the EPSS score is < 1% and the vulnerability is not listed in CISA KEV. With a CVSS score of 8.8, the flaw is considered high, and devices running earlier versions remain highly susceptible if exposed to hostile networks.
OpenCVE Enrichment
Debian DSA