CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 148.0.7778.216 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
Insufficient input validation in the WebAppInstalls component of Google Chrome for Android allows a local attacker to execute arbitrary code via a malicious file. The CVSS vector (AV:L/AC:L/PR:N/UI:R) indicates the attacker needs local access to the device and must get the target user to interact with a crafted file, but no account credentials are required. Successful exploitation gives the attacker full read, write, and execution access within the context of the Chrome process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9987 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and build pipelines, including custom-built Android-based container images that bundle a Chrome binary. Any image carrying a Chrome version below 148.0.7778.216 on Android is flagged automatically.
AvailableHarborGuard is capable of scoring this CVE at CVSS 7.8 HIGH and weighting that score against each customer environment's compliance policy to determine priority. Findings are routed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard the moment the fix version is registered in the upstream advisory. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityNot required
The attacker needs an existing shell or process on the host; no network path to the target service is required.
- AuthenticationNot required
No account credentials or privilege level are required to attempt exploitation.
- Victim interactionRequired
The target user must open or otherwise interact with a malicious file, making this a social-engineering-dependent attack.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions or specific memory layout.
Blast Radius
- A successful attacker executes arbitrary code within the Chrome process on the affected Android device.
- The attacker reads any data accessible to Chrome, including stored session tokens, saved passwords, cookies, and browsing history.
- The attacker modifies or deletes Chrome-managed storage, including cached files and locally persisted web app data.
- The attacker crashes or destabilizes the Chrome process, causing denial of service for the browser and any hosted web apps.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome for Android below version 148.0.7778.216 are matched against this CVE at ingest time and flagged as HIGH severity. A rebuilt image at the fixed version (148.0.7778.216) becomes available for affected environments as soon as the upstream fix is confirmed. Where compliance policy permits auto-remediation, HarborGuard rebuilds the affected image, executes a regression test run, and opens a pull request against affected workloads; for HIGH-severity issues, the median time from CVE publication to a merged patch PR in environments with auto-remediation enabled is around 90 minutes. For environments that cannot immediately update, consider restricting the deployment of the affected image via network-policy isolation and limiting access to the host filesystem to reduce the local-file interaction surface until the patched image is promoted.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H