Junglewise Threat Intelligence

CVE-2026-91723: Google Chrome race condition in WebAppInstalls UI spoofing

CVE-2026-91723 · Severity: low · CVSS 3.1 · Published 2026-09-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a race condition vulnerability in the WebAppInstalls component that allows an attacker to craft a malicious HTML page to spoof user interface elements. This could trick users into believing they are interacting with legitimate UI, potentially leading to phishing attacks or social engineering. The vulnerability affects Chrome versions prior to 153.0.8010.47.

Technical details

A race condition exists in the WebAppInstalls component of Google Chrome prior to version 153.0.8010.47. An attacker can exploit this vulnerability by crafting a malicious HTML page that triggers the race condition, allowing the spoofing of UI elements. The attack vector is network-based and requires user interaction (visiting a crafted webpage). While classified as Medium severity by Chromium, the CVSS score is rated at 3.1 (low). Patches are available in Chrome 153.0.8010.47 and later.

Affected products

  • Google Chrome prior to 153.0.8010.47

Timeline

  • 2026-09-15: disclosed: Published on NVD
  • 2026-09-15: patched: Chrome version 153.0.8010.47 available

References

Related threats