Executive brief
Google Chrome is a web browser used by billions of users worldwide to access websites and applications. A race condition vulnerability in the WebAppInstalls component allows an attacker to bypass web origin security policies on Android devices through social engineering combined with a co-installed application, potentially compromising the security separation between installed web applications.
Technical details
CVE-2026-79117 is a race condition vulnerability in the WebAppInstalls component of Google Chrome on Android. The vulnerability allows a remote attacker to bypass web origin policy restrictions by leveraging social engineering tactics and a co-installed application. The attack requires user interaction to be exploited. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions on Android.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 and later