Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Chrome’s WebAppInstalls feature on Android constitutes a CWE‑20 input validation weakness. A local attacker can craft an HTML page to bypass discretionary access controls, potentially exercising unauthorized local privileges and escalating privileges on the device.

Affected Systems

The vulnerability affects Google Chrome on Android, specifically versions older than 150.0.7871.47. Only the Android build is listed; no mention of desktop versions in the description.

Risk and Exploitability

The CVSS score of 9.1 reflects a high severity level, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker must have access to the device or be able to deliver the crafted HTML to the user, which implies the attacker has physical or local access. Exploitation would allow privilege escalation on the device, making the potential impact significant.

Generated by OpenCVE AI on July 21, 2026 at 17:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome on Android to version 150.0.7871.47 or later to obtain the fix.
  • Enable automatic updates for Chrome, or manually update the browser to ensure timely application of security patches.
  • If an immediate update is not possible, restrict the WebAppInstalls feature through enterprise policy or by disabling local HTML file execution to prevent exploitation.

Generated by OpenCVE AI on July 21, 2026 at 17:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Insufficient validation in Chrome WebAppInstalls allows local access bypass

Thu, 16 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Insufficient validation in Chrome WebAppInstalls allows local access bypass

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local Access Bypass via Untrusted Input Validation in Chrome WebAppInstalls

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Access Bypass via Untrusted Input Validation in Chrome WebAppInstalls

Sat, 11 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Access Bypass via WebAppInstalls in Chrome for Android

Fri, 10 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Local Access Bypass via WebAppInstalls in Chrome for Android

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via WebAppInstalls in Chrome for Android

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via WebAppInstalls in Chrome for Android

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Access Bypass via Untrusted Input in Chrome WebAppInstalls on Android

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Local Access Bypass via Untrusted Input in Chrome WebAppInstalls on Android

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Crafted HTML in Chrome's WebAppInstalls

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Crafted HTML in Chrome's WebAppInstalls

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Chrome WebAppInstalls via Unsanitized Input

Sat, 04 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Access Control Bypass in Chrome WebAppInstalls via Unsanitized Input

Sat, 04 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Google Chrome via WebAppInstalls Input Validation Vulnerability

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass in Google Chrome via WebAppInstalls Input Validation Vulnerability

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Untrusted Input in Chrome Web App Installs

Thu, 02 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via Untrusted Input in Chrome Web App Installs

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via WebAppInstalls in Chrome on Android

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Bypass via WebAppInstalls in Chrome on Android

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local WebAppInstalls Access Control Bypass in Chrome Android

Wed, 01 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local WebAppInstalls Access Control Bypass in Chrome Android

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:07:28.596Z

Reserved: 2026-06-29T23:03:33.770Z

Link: CVE-2026-13852

cve-icon Vulnrichment

Updated: 2026-07-01T14:38:00.780Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:15:09Z

Weaknesses
  • CWE-20

    Improper Input Validation