CVE-2026-17722

Google · Chrome

A use-after-free object lifecycle issue in WebView for Google Chrome on Android allows remote attackers to bypass sandbox protections via a crafted HTML page.

Executive summary

A critical sandbox escape vulnerability in Google Chrome for Android exposes devices to potential remote code execution.

Vulnerability

This is an object lifecycle vulnerability, specifically a use-after-free flaw within the WebView component. It allows an unauthenticated remote attacker who has already compromised the renderer process to escape the browser sandbox.

Business impact

The vulnerability carries a CVSS score of 8.3, indicating high severity. Successful exploitation permits an attacker to execute code outside the restricted browser environment, potentially leading to a full compromise of device integrity, theft of sensitive user data, and total loss of confidentiality.

Remediation

Immediate Action: Update Google Chrome on Android to version 151.0.7922.72 or later immediately.

Proactive Monitoring: Monitor device traffic and application logs for unusual crashes or unexpected behavior in the WebView component.

Compensating Controls: Since this is a client-side browser vulnerability, ensure that users are restricted from visiting untrusted or malicious websites that may host crafted HTML content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete sandbox bypass, this vulnerability poses a significant risk to mobile device security. Administrators and users must prioritize updating to the patched version 151.0.7922.72 to mitigate the risk of remote exploitation.