Description
Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via WebView renderer escape
Action: Patch Now
AI Analysis

Impact

The vulnerability involves an externally controlled reference within Chrome's WebView on Android. If a malicious actor manages to compromise the renderer process, a specially crafted HTML page can cause the process to escape its sandbox boundaries and run arbitrary code. The weakness is identified as CWE-610, which represents unauthorized or illegitimate access to privileged resources. The impact of such an escape is a full compromise of the device's security context for the affected user or application, potentially allowing the attacker to read, modify, or execute data beyond its normal permissions.

Affected Systems

Affected tenants are users of Google Chrome on Android devices running versions prior to 152.0.7977.65. The vulnerability specifically targets the WebView component integrated into Chrome, which is employed to display web content within applications.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3, indicating high severity and is classified as a hover of risk given its requirement for a compromised renderer process. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote attacker delivering a crafted HTML page to a user running an unpatched version of Chrome on Android. Once the renderer process is compromised, the attacker can execute code outside the sandbox, elevating privileges on the device. The lack of a publicly disclosed exploit and the high severity score suggest the risk is present but not imminent; however, any reachable renderer process would enable this attack.

Generated by OpenCVE AI on August 26, 2026 at 19:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 152.0.7977.65 or newer.
  • Ensure that the WebView component is not exposed to untrusted content without proper isolation.
  • Disable WebView for applications that handle sensitive data if an updated version cannot be deployed immediately.

Generated by OpenCVE AI on August 26, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Sat, 29 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Externally Controlled Reference in Chrome WebView Allows Renderer Process Escape
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Externally Controlled Reference in Chrome WebView Allows Renderer Process Escape

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-610
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T19:06:07.538Z

Reserved: 2026-08-25T06:12:41.603Z

Link: CVE-2026-79256

cve-icon Vulnrichment

Updated: 2026-08-26T16:50:37.683Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:20.117

Modified: 2026-08-28T20:20:07.200

Link: CVE-2026-79256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:00:11Z

Weaknesses
  • CWE-610

    Externally Controlled Reference to a Resource in Another Sphere