Executive brief
A vulnerability in Google Chrome's web application installation component could allow a malicious website to access data from other websites. This occurs if an attacker first compromises a specific internal browser process, typically by tricking a user into visiting a malicious page. Successful exploitation could lead to the unauthorized disclosure of sensitive information across different web domains.
Technical details
An improper input validation vulnerability exists in the WebAppInstalls component of Google Chrome. A remote attacker who has already compromised the renderer process can exploit this flaw by using a specially crafted HTML page to bypass cross-origin restrictions. This allows the attacker to leak data from origins other than the one they currently control. The vulnerability is addressed in Google Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.