CVE-2026-87640: Google Chrome (Android WebView) vulnerability
Published Sep 9, 2026
·Updated
Out of bounds read in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
1 affected component
Google Chrome (Android WebView)<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Android deployments using Google Chrome Android WebView versions earlier than 153.0.8010.36 are affected. The issue concerns WebView rather than the desktop Chrome product.
2
What does an attacker need to exploit it?
The attacker must first compromise the renderer process. They can then use a crafted HTML page to trigger an out-of-bounds read and access memory outside the sandbox.