Executive brief
A security issue in Google Chrome's web application installation process could allow a malicious website to trick users into believing they are interacting with a different, legitimate domain. By convincing a user to perform specific mouse or keyboard actions on a specially crafted page, an attacker can spoof the origin of a web app. This could lead to users providing sensitive information to a fraudulent site or installing malicious software under the guise of a trusted brand.
Technical details
A domain spoofing vulnerability exists in the WebAppInstalls component of Google Chrome prior to version 150.0.7871.47. The flaw stems from an incorrect security UI implementation that fails to properly represent the origin during certain user interactions. A remote attacker can exploit this by hosting a crafted HTML page and inducing a user to perform specific UI gestures. Successful exploitation allows the attacker to misrepresent the domain of a web application, potentially facilitating phishing or unauthorized data collection. The issue is addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory