Executive brief
A vulnerability in Google Chrome for Android could allow a local attacker to spoof the user interface. This occurs within the WebAppInstalls component, which handles the installation of web applications. An attacker could use a malicious file to trick users into performing unintended actions by displaying misleading information or interface elements.
Technical details
A UI spoofing vulnerability exists in Google Chrome for Android prior to version 150.0.7871.47 due to an inappropriate implementation in the WebAppInstalls component. A local attacker can exploit this by providing a specially crafted malicious file to the system. Successful exploitation allows the attacker to manipulate or spoof user interface elements, potentially leading to user confusion or social engineering attacks. The vulnerability is classified by Chromium as Low severity and was addressed in the stable channel update for version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched