Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in WebAppInstalls allows a local attacker to place a malicious file that can escape Chrome’s sandbox, potentially enabling arbitrary code execution or device compromise. The flaw carries a medium severity rating from Chromium security and is classified as CWE‑20, reflecting a lack of proper input validation.

Affected Systems

Google Chrome for Android versions prior to 150.0.7871.47 are affected. Devices running these builds can be compromised if a malicious file is introduced through the WebAppInstalls mechanism.

Risk and Exploitability

The vulnerability is local; an attacker must already have access to the device or be able to deliver a crafted file. No EPSS score is available and the flaw is not listed in CISA KEV, suggesting that exploit code may not yet be public, but the medium‑severity rating and sandbox escape potential mean that exploitation could have serious consequences. Updating Chrome to 150.0.7871.47 or later mitigates the risk promptly.

Generated by OpenCVE AI on July 1, 2026 at 01:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later immediately through the Play Store or official Android update channel.
  • Ensure Chrome is allowed to auto‑update and remove any older local installations that may remain on the device.
  • Configure device settings or user permissions to restrict or block the installation of WebAppInstalls from untrusted sources and monitor for unusual file activity.

Generated by OpenCVE AI on July 1, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Local Sandbox Escape via Malicious File in Chrome Android WebAppInstalls

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)
Weaknesses CWE-20
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-30T22:38:04.211Z

Reserved: 2026-06-29T23:03:38.833Z

Link: CVE-2026-13872

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T01:15:16Z

Weaknesses
  • CWE-20

    Improper Input Validation