Description
Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass leading to elevated privileges
Action: Apply Update
AI Analysis

Impact

Google Chrome for Android contained an incorrect authorization check in the WebAppInstalls component that allowed a remote attacker to bypass system access restrictions. The flaw could be triggered by a crafted HTML page, enabling the attacker to install or interact with web applications with elevated privileges. The weakness is a classic lack of authorization (CWE-863).

Affected Systems

Android users running Google Chrome versions prior to 155.0.8059.39 are affected. The CVE documentation does not explicitly confirm that Chrome 155.0.8059.39 and later patched the issue, though it is probable that the release includes the fix.

Risk and Exploitability

The vulnerability can be exploited remotely via an attacker‑controlled web page presented to the user. EPSS data is not available and the issue is not listed in the CISA KEV catalog, yet Chromium formally rated the severity as Medium. Even without quantitative risk metrics, the potential for privilege escalation on a mobile device indicates that the vulnerability poses a non‑negligible threat, especially to users who frequently visit untrusted sites.

Generated by OpenCVE AI on October 7, 2026 at 02:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Chrome update for Android (155.0.8059.39 or newer).
  • If an update is not immediately possible, disable or restrict the use of WebAppInstalls through enterprise policy or configuration settings.
  • Educate users to avoid opening suspicious URLs and ensure they use safe browsing tools to mitigate accidental exploitation.

Generated by OpenCVE AI on October 7, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebAppInstalls in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:15.206Z

Reserved: 2026-10-06T16:35:24.662Z

Link: CVE-2026-106324

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:18:00.677

Modified: 2026-10-07T13:38:11.190

Link: CVE-2026-106324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses