Description
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the WebAppInstalls component of Google Chrome on Android allows a local attacker to place a malicious file that will be rendered as a legitimate user interface, enabling UI spoofing. The vulnerability is identified as CWE‑451 and is considered low‑severity by Chromium security, though the CVSS score of 7.5 indicates a high impact if exploited.

Affected Systems

All Android installations of Google Chrome running any build prior to 150.0.7871.47 are vulnerable, including every release of the Chrome stable channel that has not yet been updated to that specific build or later.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact if exploited, underscoring the severity of the flaw. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV. Exploitation requires local access to the device and the ability to place a malicious file, such as via a local file transfer or file‑manager action. Based on the description, it is inferred that no remote or privilege‑elevation path is needed and there is no evidence of widespread exploitation to date.

Generated by OpenCVE AI on July 17, 2026 at 13:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or newer.
  • Enable automatic updates for Chrome on the Android device to receive future patches promptly.
  • Limit the installation of Web App Installs to trusted sources and verify file contents before opening any local file.

Generated by OpenCVE AI on July 17, 2026 at 13:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android WebAppInstalls

Wed, 15 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via WebAppInstalls in Android Chrome

Fri, 10 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via WebAppInstalls in Android Chrome

Fri, 10 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in WebAppInstalls on Android Chrome

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in WebAppInstalls on Android Chrome

Tue, 07 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Google Chrome for Android

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Google Chrome for Android

Sun, 05 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome WebAppInstalls

Sun, 05 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome WebAppInstalls

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome WebAppInstalls on Android

Sat, 04 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome WebAppInstalls on Android

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android WebAppInstalls

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android WebAppInstalls

Fri, 03 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android WebAppInstalls

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome Android WebAppInstalls

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome WebAppInstalls on Android

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local UI Spoofing via Malicious File in Chrome WebAppInstalls on Android

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious File in Chrome Android WebAppInstalls
Weaknesses CWE-1130
CWE-1161

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious File in Chrome Android WebAppInstalls
Weaknesses CWE-1130
CWE-1161

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:40:41.029Z

Reserved: 2026-06-29T23:11:44.996Z

Link: CVE-2026-14114

cve-icon Vulnrichment

Updated: 2026-07-01T14:40:36.396Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T13:45:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information