Authorization Flaw in Google Chrome Affects User Interface
CVE-2026-106270

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106270?

A vulnerability exists in Google Chrome that allows a remote attacker to spoof user interface elements by exploiting incorrect authorization in the WebAppInstalls feature. This can be achieved by serving a specially crafted HTML page, presenting potential risks to users interacting with the manipulated UI. It's crucial for users to keep their browsers updated to mitigate exposure to such vulnerabilities.

Affected Version(s)

Chrome 155.0.8059.39

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.