Junglewise Threat Intelligence

CVE-2026-13852: Google Chrome for Android DAC bypass in WebAppInstalls

CVE-2026-13852 · Severity: info · CVSS 7.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Android's web application installation component. An attacker could use a specially crafted web page to bypass security controls that normally restrict access to certain data or functions. This could allow an unauthorized party to perform actions on the device that should be restricted by the browser's security policy.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebAppInstalls component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when processing web application installation requests. A local attacker can exploit this by enticing a user to visit a malicious or crafted HTML page, leading to a bypass of discretionary access control (DAC) mechanisms. This could allow the attacker to perform unauthorized operations or access restricted resources within the context of the browser. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats