Executive brief
A security issue in Google Chrome's web application installation process could allow a malicious website to misrepresent its identity. By showing a deceptive user interface, an attacker could trick a user into installing a malicious web app or performing actions under the false impression that they are interacting with a trusted site. This type of spoofing can lead to unauthorized access to user data or the installation of unwanted software.
Technical details
A UI spoofing vulnerability exists in the WebAppInstalls component of Google Chrome. The flaw stems from an incorrect security UI implementation that fails to properly validate or display origin information during the web app installation flow. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to overlay or manipulate the installation dialog. Successful exploitation enables the attacker to perform UI spoofing, potentially leading to user confusion or the installation of malicious web applications under a spoofed identity. The issue is resolved in Chrome version 150.0.7871.46.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 151 promoted to stable channel containing the fix.
- 2026-07-01: disclosed: CVE published to NVD.