Junglewise Threat Intelligence

CVE-2026-17872: Google Chrome for Android cryptographic flaw in WebAppInstalls

CVE-2026-17872 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android contains a security flaw in the component responsible for installing web applications. A local attacker could use a specially crafted web page to bypass the browser's security sandbox, which is designed to keep malicious code isolated from the rest of the device. If successful, this could allow an attacker to gain unauthorized access to other parts of the mobile operating system or user data.

Technical details

A cryptographic flaw exists in the WebAppInstalls component of Google Chrome for Android prior to version 151.0.7922.72. The vulnerability allows a local attacker to achieve a sandbox escape by enticing a user to visit or interact with a specially crafted HTML page. By exploiting weaknesses in how web applications are cryptographically verified or handled during installation, the attacker can break out of the restricted browser environment. This issue is tracked as CVE-2026-17872 and was addressed in the stable channel update for version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats