
🚨 CRITICAL - Chrome Android WebAppInstalls input validation flaw enables sandbox escape (CVE-2026-13872) Google Chrome on Android prior to 150.0.7871.47 is vulnerable to insufficient validation of untrusted input in the WebAppInstalls component when handling Web App install-related data. The root cause is improper input validation/trust boundary failure, allowing crafted file content to be processed in an unsafe way. An attacker can exploit this by getting a victim to open or import a malicious file (e.g., via download, share intent, or attachment) that triggers the vulnerable WebAppInstalls handling path, requiring only local user interaction rather than elevated privileges. Successful exploitation can enable a sandbox escape, potentially leading to code execution in a higher-privileged context, data access beyond the renderer sandbox, and broader device compromise depending on chained bugs. 👉 Affected: Google Chrome for Android < 150.0.7871.47 | Upgrade to 150.0.7871.47 or later
Post summary
This post discloses CVE-2026-13872, a sandbox escape flaw in Chrome Android’s WebAppInstalls component, and recommends users upgrade to version 150.0.7871.47 or later.
