Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw involves insufficient validation of untrusted input in WebAppInstalls on Android, which allows a local attacker to bypass discretionary access control. This weakness, classified as CWE-20, permits an attacker to elevate privileges by executing crafted HTML content within Chrome, leading to unauthorized data access and potential further compromise of device resources.

Affected Systems

Google Chrome on Android devices running any version prior to 150.0.7871.47 is affected. The vulnerability resides in the WebAppInstalls component of the Chrome browser.

Risk and Exploitability

The vulnerability can be exploited by a local attacker who can open a malicious HTML page within Chrome. The EPSS score is < 1%, while the CVSS score of 9.1 indicates high severity; the vulnerability is rated high in Chromium’s internal severity, indicating that exploitation is realistically possible and could lead to a local privilege escalation or broader access to protected resources. The flaw is not listed in the CISA KEV catalog, but its local nature and high severity warrant immediate patching.

Generated by OpenCVE AI on July 17, 2026 at 14:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome on Android to version 150.0.7871.47 or later when available
  • If an upgrade cannot be applied, disable or remove the WebAppInstalls feature via Chrome settings or enterprise policy to prevent the flaw from being exploitable
  • Restrict device permissions and user access to the local file system and web content to reduce the ability of a local attacker to load malicious HTML pages

Generated by OpenCVE AI on July 17, 2026 at 14:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Insufficient validation of untrusted input in WebAppInstalls allows local attacker to bypass discretionary access control via crafted HTML

Thu, 16 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Insufficient validation of untrusted input in WebAppInstalls allows local attacker to bypass discretionary access control via crafted HTML

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Malicious HTML in Chrome WebAppInstalls on Android

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Malicious HTML in Chrome WebAppInstalls on Android

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Untrusted Input in Chrome WebAppInstalls on Android

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Untrusted Input in Chrome WebAppInstalls on Android

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via WebAppInstalls Input Validation Flaw in Chrome Android

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via WebAppInstalls Input Validation Flaw in Chrome Android

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via WebAppInstalls in Google Chrome on Android

Mon, 06 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via WebAppInstalls in Google Chrome on Android

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Chrome WebAppInstalls via Crafted HTML Page

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Chrome WebAppInstalls via Crafted HTML Page

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Chrome Android WebAppInstalls via Untrusted Input

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Chrome Android WebAppInstalls via Untrusted Input

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Crafted HTML in Chrome's WebAppInstalls Component

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Crafted HTML in Chrome's WebAppInstalls Component

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome WebAppInstalls Allows Local Access Control Bypass

Wed, 01 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome WebAppInstalls Allows Local Access Control Bypass

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Enables Access Control Bypass in Chrome's WebAppInstalls on Android

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Enables Access Control Bypass in Chrome's WebAppInstalls on Android

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:07:38.201Z

Reserved: 2026-06-29T23:03:33.480Z

Link: CVE-2026-13851

cve-icon Vulnrichment

Updated: 2026-07-01T14:39:07.401Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:00:10Z

Weaknesses
  • CWE-20

    Improper Input Validation