Description
Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

An attacker who has already compromised the renderer process of Chrome can use a crafted HTML page that exploits incorrect authorization in the WebAppInstalls component. This flaw allows the attacker to bypass Chrome’s site isolation, gaining permission to install or modify web applications on the local machine with the privileges of the compromised renderer. Because the vulnerability resides in the renderer, the attacker’s local privileges are typically confined to the user who ran Chrome, but the ability to install applications expands the attack surface for further malware installation or data exfiltration.

Affected Systems

Google Chrome versions prior to 153.0.8010.36 are affected. The vulnerability specifically impacts the WebAppInstalls feature in desktop builds of Chrome; the affected component is present in all mainstream operating systems that run the stable channel.

Risk and Exploitability

The flaw carries a medium severity rating. Exploitation requires the attacker to first compromise the renderer process—a process that is largely sandboxed, but can be achieved by social engineering such as phishing or malicious extensions. Once the Renderer is compromised, the attacker can craft a malicious HTML page to convince the user to load it, thereby bypassing site isolation. The CVSS score of 6.5 reflects functional impact and limited exploitation potential. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, so the likelihood of widespread exploitation is currently unknown, but the attack vector is feasible under the right conditions.

Generated by OpenCVE AI on September 10, 2026 at 23:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Google Chrome update (153.0.8010.36 or newer) which contains the authorized WebAppInstalls code fix
  • Configure Chromeforce site isolation for all sites’ flag in chrome://flags
  • Educate users to avoid opening malicious HTML pages and to scrutinize unexpected installation prompts

Generated by OpenCVE AI on September 10, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Fri, 11 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title WebAppInstalls Authorization Bypass in Google Chrome via Renderer Compromise

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title WebAppInstalls Authorization Bypass in Google Chrome via Renderer Compromise

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T18:31:55.290Z

Reserved: 2026-09-08T22:41:14.042Z

Link: CVE-2026-87580

cve-icon Vulnrichment

Updated: 2026-09-10T18:31:14.388Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:15.813

Modified: 2026-09-11T14:39:26.440

Link: CVE-2026-87580

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses