Description
Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Published: 2026-09-29
Score: 2.9 Low
EPSS: n/a
KEV: No
Impact: Cross‑origin data leakage via improper authorization in WebAPKs
Action: Apply Update
AI Analysis

Impact

A flaw in the authorization logic for WebAPKs in Google Chrome for Android allows a local attacker to read data from WebAPKs belonging to another origin. The vulnerability is identified as an improper privilege management weakness (CWE‑863). An attacker who can co‑install a malicious app can leverage this flaw to obtain confidential information from a co‑installed WebAPK that normally would be protected by origin boundaries. The impact is primarily the compromise of information confidentiality and could be used to exfiltrate sensitive data exposed by the affected WebAPK.

Affected Systems

The vulnerability affects Google Chrome on Android installations running any version earlier than 154.0.8037.57. Systems with Chrome earlier than this patch level are vulnerable unless an alternative security measure is applied.

Risk and Exploitability

The CVSS score of 2.9 indicates a medium severity assessment. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is local and requires installation of a malicious co‑app, the likelihood of exploitation is moderate and depends on user behavior and device policies. Organizations that allow installation of apps from unknown sources or that configure WebAPKs with sensitive data should treat this as a medium‑risk issue and consider immediate patching or additional controls.

Generated by OpenCVE AI on September 29, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 154.0.8037.57 or later, which removes the improper authorization logic in WebAPKs.
  • Restrict installation of apps from unknown sources or untrusted repositories to reduce the chance a malicious co‑app can be installed.
  • Configure or disable the WebAPK feature for applications that handle highly sensitive data to eliminate the attack surface.
  • If updating is not immediately possible, enforce strict app permission policies and monitor for suspicious data access patterns associated with WebAPKs.

Generated by OpenCVE AI on September 29, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Tue, 29 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass in WebAPKs Allows Cross‑Origin Data Leakage

Tue, 29 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T19:18:22.291Z

Reserved: 2026-09-22T05:07:58.097Z

Link: CVE-2026-95302

cve-icon Vulnrichment

Updated: 2026-09-29T19:18:16.562Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:22.193

Modified: 2026-09-29T20:17:29.810

Link: CVE-2026-95302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T22:15:08Z

Weaknesses