CVE-2026-13852: Insufficient validation of untrusted input in WebAppInstalls in Google ...

Severity: Critical

CVSS Score: 9.1

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)