Executive brief
A security vulnerability in Google Chrome on Android could allow a malicious file to execute unauthorized code on a user's device. This occurs due to how the browser handles web application installations. If exploited, an attacker could potentially gain control over the application's functions or access sensitive data stored within the browser environment.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebAppInstalls component of Google Chrome for Android. The flaw allows a local attacker to achieve arbitrary code execution by providing a specially crafted malicious file that is processed during the web app installation flow. The vulnerability stems from insufficient validation of untrusted input, which can be leveraged to bypass security boundaries. This issue is resolved in version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and mobile versions.
- 2026-05-28: disclosed: CVE published to the NVD.