Executive brief
Google Chrome on Android contains a missing authorization flaw in the WebAppInstalls component that allows an attacker who has already compromised the browser's rendering process to access sensitive information. An attacker exploiting this vulnerability could steal user data or perform unauthorized actions within web applications installed through Chrome.
Technical details
This vulnerability is a missing authorization flaw in Chrome's WebAppInstalls component affecting Android versions prior to 152.0.7977.65. The vulnerability allows a remote attacker who has already compromised the renderer process to obtain sensitive information by crafting a malicious HTML page. The attack requires prior compromise of the renderer process, limiting the attack vector to scenarios where an attacker has already achieved code execution in that context. The vulnerability has been patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65