Junglewise Threat Intelligence

CVE-2026-79213: Google Chrome incorrect authorization in WebAppInstalls on Android

CVE-2026-79213 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android contains an authorization flaw in its web app installation feature that allows attackers to bypass system-level access restrictions. A remote attacker can exploit this vulnerability by hosting a specially crafted HTML page, potentially gaining unauthorized access to protected functionality without user awareness or proper permission checks.

Technical details

This vulnerability is an incorrect authorization flaw in Chrome's WebAppInstalls component on Android. The root cause involves improper validation of user permissions when handling web app installation requests, allowing a remote attacker to bypass system access restrictions via a crafted HTML page. The attack requires no authentication but does require the target user to visit a malicious webpage. An attacker can leverage this to perform unauthorized web app installations or escalate privileges beyond what the browser's security model should permit. The vulnerability was patched in Chrome 152.0.7977.65 for Android.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 for Android

References

Related threats