Junglewise Threat Intelligence

CVE-2026-17819: Google Chrome UI spoofing in WebAppInstalls

CVE-2026-17819 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's web application installation process could allow a malicious website to misrepresent its identity. By using a specially crafted webpage, an attacker could trick users into believing they are interacting with a legitimate application or interface. This type of spoofing is often used to facilitate phishing attacks or to gain unauthorized trust from the user.

Technical details

A UI spoofing vulnerability exists in the WebAppInstalls component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly validate or display interface elements during the web app installation flow. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to spoof user interface elements, potentially leading to user confusion or successful phishing attempts. The issue is resolved in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats