Junglewise Threat Intelligence

CVE-2026-11127: Google Chrome for Android domain spoofing in WebAPKs

CVE-2026-11127 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android allows a remote attacker to perform domain spoofing. This occurs through the use of specially crafted WebAPKs, which are packages used to install web applications as native-like apps on Android. An attacker could use this to trick users into believing they are interacting with a legitimate website or service, potentially leading to the theft of login credentials or other sensitive information.

Technical details

An inappropriate implementation in the WebAPK component of Google Chrome for Android allowed for domain spoofing. WebAPKs are the mechanism by which Progressive Web Apps (PWAs) are installed on Android devices. By crafting a malicious WebAPK, a remote attacker could misrepresent the origin domain of the application. This vulnerability requires user interaction to install or interact with the crafted WebAPK. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel.
  • 2026-06-04: disclosed: CVE published.

References

Related threats