Executive brief
Google Chrome is a widely used web browser. A vulnerability in the component responsible for installing web applications could allow a malicious website to perform unauthorized data operations on a user's Windows computer. This could potentially lead to the exposure of sensitive information or the modification of local files if a user visits a specially crafted webpage.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebAppInstalls component of Google Chrome on Windows. The flaw is triggered when the browser processes untrusted input during web app installation routines. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, enabling arbitrary read and write operations within the context of the browser. This issue was addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory
- 2026-06-30: patched