Junglewise Threat Intelligence

CVE-2026-13851: Google Chrome for Android DAC bypass in WebAppInstalls

CVE-2026-13851 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome on Android could allow a local attacker to bypass security controls. By using a specially crafted web page, an attacker could circumvent discretionary access controls within the web application installation component. This could lead to unauthorized actions or access to data that should normally be restricted by the browser's security boundaries.

Technical details

An insufficient validation of untrusted input vulnerability exists in the WebAppInstalls component of Google Chrome for Android. A local attacker can exploit this by tricking a user into visiting or interacting with a specially crafted HTML page. Successful exploitation allows the attacker to bypass discretionary access control (DAC) mechanisms. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. Chromium developers have assigned this a 'High' severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats