Executive brief
A vulnerability in Google Chrome allowed Progressive Web Apps (PWAs) to be installed on a user's device without their knowledge or consent. This could occur if an attacker first compromises the browser's rendering process, potentially leading to the presence of unauthorized applications on the system. Users are protected by updating to the latest version of the Chrome browser.
Technical details
This vulnerability is classified as insufficient policy enforcement (CWE-1268) within the Progressive Web Apps (PWA) component of Google Chrome. A remote attacker who has successfully achieved code execution within a compromised renderer process could bypass standard installation prompts. By utilizing a specially crafted HTML page, the attacker can force the installation of a PWA without the required user interaction or consent. This issue was addressed in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome < 147.0.7727.55
Timeline
- 2026-02-25: disclosed: Reported to Chromium by Tianyi Hu
- 2026-04-07: patched: Fixed in Chrome stable channel update 147.0.7727.55
- 2026-04-08: advisory: NVD publication date