SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15115

LOW · CVSS 3.3 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A local attacker can exploit insufficient validation of untrusted input in WebAppInstalls within Google Chrome on Android, allowing them to bypass the same origin policy through a specially crafted HTML page. While the vulnerability is rated low in severity, it poses a significant risk to users running affected versions prior to 150.0.7871.115. Android developers and security teams should prioritize this issue to mitigate potential exploitation.

CVE
CVE-2026-15115
Severity
LOW
CVSS
3.3
EPSS
0.09%
Android Chrome

Original NVD Description

Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)