Executive brief
Google Chrome is a widely used web browser. A security flaw in the way it handles web application installations could allow a malicious website to bypass standard security boundaries. If exploited, this could allow an attacker to access data from other websites you have open, potentially leading to the theft of sensitive information or unauthorized actions on other sites.
Technical details
A Same Origin Policy (SOP) bypass vulnerability exists in the WebAppInstalls component of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce origin boundaries during web app installation processes. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass SOP, potentially enabling cross-origin data access or unauthorized interactions with other web domains. The issue is resolved in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched