Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability results from insufficient validation of untrusted input in the WebAppInstalls component of Google Chrome on Windows, classified as CWE-20. A remote attacker can supply a crafted HTML page that, when the user performs specific UI gestures, causes arbitrary code to execute within the browser, potentially taking control of the affected system.

Affected Systems

Google Chrome for Windows versions earlier than 150.0.7871.47 are affected. Any user running these releases may be vulnerable if they view a maliciously constructed page and perform the required gestures.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Exploitation requires user interaction with a malicious webpage.

Generated by OpenCVE AI on August 4, 2026 at 08:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 150.0.7871.47 or later on all affected machines. This upgrade fixes the CWE‑20 untrusted input validation issue in the WebAppInstalls component.
  • Enable automatic updates so future security releases are applied promptly.
  • If upgrading is not immediately possible, apply a temporary mitigation by disabling the WebAppInstalls feature or restricting content to trusted domains, which reduces the risk associated with the CWE‑20 flaw until a patch is available.
  • If you must continue to use the current version, avoid interacting with suspicious or unfamiliar webpages that prompt unusual UI gestures; no official workaround is available.

Generated by OpenCVE AI on August 4, 2026 at 08:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome WebAppInstalls Enables Remote Code Execution

Wed, 29 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome WebAppInstalls Enables Remote Code Execution

Sun, 26 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome WebAppInstalls Allows Remote Code Execution on Windows

Tue, 21 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome WebAppInstalls Allows Remote Code Execution on Windows

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in WebAppInstalls Facilitates Remote Code Execution

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in WebAppInstalls Facilitates Remote Code Execution

Mon, 13 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Untrusted WebAppInstalls Input in Chrome on Windows

Sun, 12 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Untrusted WebAppInstalls Input in Chrome on Windows

Sat, 11 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Insufficient WebAppInstalls Input Validation in Chrome for Windows

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Insufficient WebAppInstalls Input Validation in Chrome for Windows

Thu, 09 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in WebAppInstalls Allows Remote Code Execution

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in WebAppInstalls Allows Remote Code Execution

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Flaw Enables Remote Code Execution via Malicious Web Page in Google Chrome on Windows

Mon, 06 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Flaw Enables Remote Code Execution via Malicious Web Page in Google Chrome on Windows

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebAppInstalls Input Validation in Chrome on Windows

Sat, 04 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebAppInstalls Input Validation in Chrome on Windows

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unvalidated Input in Chrome WebApp Installs Enables Remote Code Execution

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unvalidated Input in Chrome WebApp Installs Enables Remote Code Execution

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome WebAppInstalls Allows Remote Code Execution

Thu, 02 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome WebAppInstalls Allows Remote Code Execution

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Input in Chrome WebAppInstalls

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Input in Chrome WebAppInstalls

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebAppInstalls Input Validation Flaw

Wed, 01 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebAppInstalls Input Validation Flaw

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:55.062Z

Reserved: 2026-06-29T23:03:19.400Z

Link: CVE-2026-13794

cve-icon Vulnrichment

Updated: 2026-07-01T13:43:28.378Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation