Executive brief
A security vulnerability has been identified in Google Chrome for Android within the component responsible for installing web applications. This flaw could allow a malicious website or local attacker to bypass the browser's Same Origin Policy, which is a fundamental security barrier that prevents websites from accessing each other's data. If exploited, this could lead to unauthorized access to sensitive information or interactions with other web services on the user's device.
Technical details
This vulnerability is classified as an improper input validation flaw (CWE-20) within the WebAppInstalls component of Google Chrome for Android. The root cause is insufficient validation of untrusted input, which can be exploited by a local attacker or a malicious site via a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Same Origin Policy (SOP), potentially leading to cross-origin data access or unauthorized actions. The issue was addressed in Google Chrome version 150.0.7871.115. Access to specific bug details remains restricted to prevent further exploitation until a majority of users have updated.
Affected products
- Google Space Chrome prior to 150.0.7871.115
Timeline
- 2026-06-06: disclosed: Reported by Google internal researchers
- 2026-07-08: patched: Fixed in version 150.0.7871.115
- 2026-07-08: advisory