Description
Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web origin policy bypass via co-installed app
Action: Update
AI Analysis

Impact

A race condition in the WebAppInstalls component of Google Chrome on Android allows a remote attacker, who can rely on social engineering, to bypass the web origin policy. When successfully exploited, the attacker can cause Chrome to treat a malicious co‑installed application as a trusted web origin, potentially exposing user data or enabling further attacks within the browser context.

Affected Systems

The vulnerability exists in Google Chrome for Android versions prior to 152.0.7977.65. All Android devices running any unsupported Chrome build are at risk. Chrome versions 152.0.7977.65 and later have the fix applied.

Risk and Exploitability

The flaw is a race condition (CWE-362) that can be exploited remotely through a malicious Android application that is co‑installed with Chrome. Because the attack relies on social engineering to install the co-app, the primary attack vector is user interaction. The CVSS score is 4.3 and the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The Chromium advisory rates the severity as high, indicating a significant risk if the flaw is leveraged.

Generated by OpenCVE AI on August 28, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Android devices to Chrome 152.0.7977.65 or newer.
  • Configure device policies to restrict installation of unknown or untrusted Android applications.
  • Enforce safe‑install practices and educate users to avoid granting permissions to suspicious apps.

Generated by OpenCVE AI on August 28, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Race condition enabling web origin policy bypass via co‑installed app in Chrome Android

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Race condition enabling web origin policy bypass via co‑installed app in Chrome Android

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Race condition in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a co-installed app. (Chromium security severity: High)
Weaknesses CWE-362
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:09.467Z

Reserved: 2026-08-25T06:09:48.896Z

Link: CVE-2026-79117

cve-icon Vulnrichment

Updated: 2026-08-27T20:32:50.077Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:06.770

Modified: 2026-08-28T14:37:57.497

Link: CVE-2026-79117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:45:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')