Improper Authorization Flaw in WebView for Google Chrome on Android Devices
CVE-2026-102327

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102327?

An improper authorization vulnerability was identified in the WebView component of Google Chrome for Android prior to version 154.0.8037.92. This flaw could allow an attacker who has compromised the renderer process of the browser to execute arbitrary code outside of the sandbox environment by leveraging a specifically crafted HTML page. Users of affected versions are advised to update their browsers to mitigate potential security risks associated with this vulnerability.

Affected Version(s)

Chrome 154.0.8037.92

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.