Impact
Missing authorization in the WebAppInstalls feature of Google Chrome allows an attacker who has compromised the renderer process and used social engineering to load a crafted HTML page to execute arbitrary code outside the sandbox. The flaw enables code execution on the user's machine without requiring additional privileges, thereby granting the attacker full control over the victim’s system.
Affected Systems
All users who run Google Chrome versions earlier than 155.0.8059.39 on desktop platforms are affected. The vulnerability was fixed in the 155.0.8059.39 update released in October 2026.
Risk and Exploitability
The vulnerability is rated with a high severity and has a CVSS score of 8.3. No EPSS score is available and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to compromise the renderer process and coerce the user into opening a malicious page, so the likelihood of real-world exploitation is limited but still significant for sophisticated threat actors.
OpenCVE Enrichment