Description
Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Missing Authorization
Action: Immediate Patch
AI Analysis

Impact

Missing authorization in the WebAppInstalls feature of Google Chrome allows an attacker who has compromised the renderer process and used social engineering to load a crafted HTML page to execute arbitrary code outside the sandbox. The flaw enables code execution on the user's machine without requiring additional privileges, thereby granting the attacker full control over the victim’s system.

Affected Systems

All users who run Google Chrome versions earlier than 155.0.8059.39 on desktop platforms are affected. The vulnerability was fixed in the 155.0.8059.39 update released in October 2026.

Risk and Exploitability

The vulnerability is rated with a high severity and has a CVSS score of 8.3. No EPSS score is available and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires an attacker to compromise the renderer process and coerce the user into opening a malicious page, so the likelihood of real-world exploitation is limited but still significant for sophisticated threat actors.

Generated by OpenCVE AI on October 7, 2026 at 02:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or later on all affected systems.
  • Restrict or disable WebAppInstalls from untrusted origins by configuring Chrome policies.
  • Limit user exposure by monitoring for suspicious renderer activity and applying least privilege controls to the browser sandbox.

Generated by OpenCVE AI on October 7, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Missing Authorization in Chrome WebAppInstalls

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Missing Authorization in Chrome WebAppInstalls
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in WebAppInstalls in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:50.226Z

Reserved: 2026-10-06T16:30:44.424Z

Link: CVE-2026-106194

cve-icon Vulnrichment

Updated: 2026-10-06T20:00:20.692Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:45.557

Modified: 2026-10-07T04:17:49.560

Link: CVE-2026-106194

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:30:12Z

Weaknesses