Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in the WebAppInstalls component of Google Chrome for Android enables a local attacker to craft an HTML page that bypasses the browser's same-origin policy. The primary impact of this weakness is that an attacker can read or modify data belonging to a different origin within the device's browser context, potentially exposing sensitive information or executing arbitrary scripts. The flaw is a classic input validation error and is mapped to CWE-20.

Affected Systems

Google Chrome for Android, all releases prior to version 150.0.7871.115. The vulnerability is specific to the Chrome browser on Android and does not affect later releases or other platforms.

Risk and Exploitability

The3 indicates of less than 1 % suggests that exploitation is unlikely at present. No publicly documented exploitation has been reported. The attack requires local access to the device and the ability to serve or open a specially crafted HTML page. Although the flaw is categorized as \"High\" in Chromium's internal severity, the overall risk to a general user base remains low due to the local-only nature of the attack and the lack of widespread exploitation evidence.

Generated by OpenCVE AI on July 26, 2026 at 16:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome for Android to version 150.0.7871.115 or newer, which corrects the input-validation bug in WebAppInstalls.
  • If an immediate update is not feasible, disable WebAppInstalls or any feature that can invoke it via a local content policy, for example by setting the appropriate device-policy flag or using a Chrome extension that blocks the directive.
  • Apply device or network filtering to prevent the display of locally generated pages that could trigger the flaw, thereby mitigating the risk of a same-origin policy breach.

Generated by OpenCVE AI on July 26, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Sun, 26 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass in Chrome Android via WebAppInstalls

Wed, 22 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via WebAppInstalls in Chrome for Android

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Same-Origin Policy Bypass via WebAppInstalls in Chrome for Android

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass via WebAppInstalls Input Validation Flaw in Google Chrome for Android

Tue, 14 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass via WebAppInstalls Input Validation Flaw in Google Chrome for Android

Mon, 13 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Policy Bypass via WebAppInstalls in Chrome for Android

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Policy Bypass via WebAppInstalls in Chrome for Android

Sat, 11 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass via WebAppInstalls in Chrome for Android

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass via WebAppInstalls in Chrome for Android

Thu, 09 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass via WebAppInstalls Input Validation Failure in Android Chrome

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local Same-Origin Policy Bypass via WebAppInstalls Input Validation Failure in Android Chrome

Thu, 09 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:32:24.506Z

Reserved: 2026-07-08T17:07:40.716Z

Link: CVE-2026-15115

cve-icon Vulnrichment

Updated: 2026-07-09T10:32:21.039Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:30:06Z

Weaknesses
  • CWE-20

    Improper Input Validation