Junglewise Threat Intelligence

CVE-2026-10923: Google Chrome for Android use after free in WebAppInstalls

CVE-2026-10923 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a local attacker to execute unauthorized code on a user's device. This issue occurs within the component responsible for installing web applications. If exploited, an attacker could potentially gain control over the browser or access sensitive user data by tricking a user into opening a malicious file.

Technical details

A use-after-free (UAF) vulnerability exists in the WebAppInstalls component of Google Chrome on Android. The flaw is triggered when the application attempts to use memory that has already been deallocated, specifically during the processing of web app installations. A local attacker can exploit this by providing a specially crafted malicious file to the system. Successful exploitation could lead to arbitrary code execution within the context of the browser process. The vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-04: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats