Impact
CVE‑2026‑7342 is a use‑after‑free vulnerability in the WebView component of Google Chrome on Android. The flaw allows a remote attacker to craft a malicious HTML page that triggers the freed memory to be accessed again, resulting in execution of arbitrary code inside the sandbox. The vulnerability is classified as high severity.
Affected Systems
The affected product is Google Chrome WebView on Android, specifically versions earlier than 147.0.7727.138. Devices running these versions can be impacted by a maliciously crafted HTML page delivered over the network.
Risk and Exploitability
The attack vector is remote, requiring an attacker to deliver a specially formed HTML page to a vulnerable device. While exploitation has not been confirmed in the wild, the absence of an EPSS score suggests limited observable activity and the weakness is not listed in CISA KEV. The vulnerability remains a significant risk if the device is connected to potentially hostile networks, given its high severity.
OpenCVE Enrichment