CVE-2026-17722
Google · Chrome
A use-after-free object lifecycle issue in WebView for Google Chrome on Android allows remote attackers to bypass sandbox protections via a crafted HTML page.
Executive summary
A critical sandbox escape vulnerability in Google Chrome for Android exposes devices to potential remote code execution.
Vulnerability
This is an object lifecycle vulnerability, specifically a use-after-free flaw within the WebView component. It allows an unauthenticated remote attacker who has already compromised the renderer process to escape the browser sandbox.
Business impact
The vulnerability carries a CVSS score of 8.3, indicating high severity. Successful exploitation permits an attacker to execute code outside the restricted browser environment, potentially leading to a full compromise of device integrity, theft of sensitive user data, and total loss of confidentiality.
Remediation
Immediate Action: Update Google Chrome on Android to version 151.0.7922.72 or later immediately.
Proactive Monitoring: Monitor device traffic and application logs for unusual crashes or unexpected behavior in the WebView component.
Compensating Controls: Since this is a client-side browser vulnerability, ensure that users are restricted from visiting untrusted or malicious websites that may host crafted HTML content.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for complete sandbox bypass, this vulnerability poses a significant risk to mobile device security. Administrators and users must prioritize updating to the patched version 151.0.7922.72 to mitigate the risk of remote exploitation.