Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in WebAppInstalls allows a local attacker to place a malicious file that can escape Chrome’s sandbox, potentially leading to arbitrary code execution or device compromise on Android. The flaw is classified as CWE‑20 and is rated medium severity by Chromium security, but the CVSS score of 9.1 indicates high potential impact.

Affected Systems

Google Chrome on Android versions prior to 150.0.7871.47 are vulnerable when a malicious file is introduced through WebAppInstalls.

Risk and Exploitability

Based on the description, it is inferred that the CVSS score of 9.1 signals a severe risk, while the EPSS score of less than 1% and its absence from the CISA KEV catalog indicate a low probability of exploitation. However, because the flaw permits sandbox escape, successful exploitation could yield arbitrary code execution. The vulnerability requires local access and the ability to supply a malicious file. The exploitation scenario presumes the attacker can place a malicious file in a location WebAppInstalls.

Generated by OpenCVE AI on July 21, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later to address the input validation flaw identified as CWE‑20 that could allow a sandbox escape.
  • If updating is not feasible, disable Chrome’s WebAppInstalls feature or restrict it to trusted sources so that untrusted files cannot be installed locally.
  • On managed devices, enforce a policy that blocks local file installation of web apps and monitor for suspicious files, ensuring that only verified origins are allowed to install web applications.

Generated by OpenCVE AI on July 21, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious WebApp Install in Chrome for Android

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title WebAppInstalls Insufficient Input Validation Enabling Sandbox Escape via Malicious File

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title WebAppInstalls Insufficient Input Validation Enabling Sandbox Escape via Malicious File

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local Application of Malicious File Leads to Chrome Sandbox Escape on Android

Tue, 07 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Application of Malicious File Leads to Chrome Sandbox Escape on Android

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome WebAppInstalls Sandbox Escape via Malicious File

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome WebAppInstalls Sandbox Escape via Malicious File

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Malicious WebAppInstalls in Chrome on Android

Sat, 04 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Malicious WebAppInstalls in Chrome on Android

Sat, 04 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious WebAppInstalls in Chrome for Android

Sat, 04 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious WebAppInstalls in Chrome for Android

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Local Chrome Android Sandbox Escape via Malicious File

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Local Chrome Android Sandbox Escape via Malicious File

Thu, 02 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls

Thu, 02 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls

Wed, 01 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls on Android

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome WebAppInstalls on Android

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome Android WebAppInstalls

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome Android WebAppInstalls

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:06:19.206Z

Reserved: 2026-06-29T23:03:38.833Z

Link: CVE-2026-13872

cve-icon Vulnrichment

Updated: 2026-07-01T14:26:42.629Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:15:09Z

Weaknesses
  • CWE-20

    Improper Input Validation