Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14122

CVE-2026-14122: Google Chrome RCE Vulnerability

CVE-2026-14122 is a remote code execution vulnerability in Google Chrome on Windows caused by insufficient input validation in WebAppInstalls. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2026-14122 Overview

CVE-2026-14122 is an input validation vulnerability in the WebAppInstalls component of Google Chrome on Windows. Versions prior to 150.0.7871.47 fail to properly validate untrusted input passed to the web application installation flow. A remote attacker can exploit the flaw by convincing a user to visit a crafted HTML page. Successful exploitation permits arbitrary read and write operations within the browser context. The issue is classified under CWE-20: Improper Input Validation. Chromium project maintainers rated the internal security severity as Low, while the NVD assigned a higher score based on confidentiality and integrity impact.

Critical Impact

Remote attackers can trigger arbitrary read/write operations against a victim's Chrome browser on Windows by luring the user to a malicious page, bypassing the security boundary of the WebAppInstalls flow.

Affected Products

  • Google Chrome on Windows prior to 150.0.7871.47
  • Microsoft Windows (host operating system)
  • Chromium-based deployments using the vulnerable WebAppInstalls component

Discovery Timeline

  • 2026-06-30 - CVE-2026-14122 published to the National Vulnerability Database
  • 2026-07-01 - Last updated in NVD database
  • 2026-06 - Google released the Stable Channel update addressing the issue, per the Google Chrome Stable Update

Technical Details for CVE-2026-14122

Vulnerability Analysis

The vulnerability resides in the WebAppInstalls subsystem of Chrome on Windows. This component handles Progressive Web App (PWA) installation requests initiated from web content. The subsystem accepts installation metadata and file-related parameters supplied by the page. Chrome versions before 150.0.7871.47 do not adequately validate this untrusted input before acting on it. An attacker exploits the gap by hosting a crafted HTML page that supplies malicious parameters to the installation flow. Because the flow requires the user to interact with an install prompt or trigger install-related surfaces, exploitation depends on user interaction. Once triggered, the flaw enables arbitrary read and write operations, undermining the confidentiality and integrity of user data accessible to the browser process.

Root Cause

The root cause is improper input validation [CWE-20] within the WebAppInstalls code path. Parameters originating from the untrusted renderer or web content are not sufficiently sanitized before being used in privileged file or resource operations. This allows attacker-controlled values to influence read and write targets.

Attack Vector

Exploitation is network-based and requires user interaction. An attacker hosts a crafted HTML page and lures the victim to visit it in a vulnerable Chrome build on Windows. The page interacts with the WebAppInstalls API surface using malicious inputs. When the victim proceeds through the install-related interaction, the browser performs unauthorized read or write actions. See the Chromium Issue Tracker Entry for maintainer discussion.

Detection Methods for CVE-2026-14122

Indicators of Compromise

  • Chrome installations on Windows reporting a version earlier than 150.0.7871.47 in chrome://version.
  • Unexpected PWA or web app entries created under the Chrome user data directory shortly after browsing an untrusted site.
  • Unusual file read or write activity by chrome.exe targeting paths outside the standard profile directories.

Detection Strategies

  • Inventory browser versions across the fleet and flag Windows endpoints running Chrome builds below 150.0.7871.47.
  • Monitor process telemetry for chrome.exe performing file operations outside expected profile, cache, and extension directories.
  • Correlate outbound HTTP(S) traffic to newly seen domains immediately preceding anomalous Chrome file activity.

Monitoring Recommendations

  • Enable browser version reporting through endpoint management or Chrome Enterprise cloud policies.
  • Alert on creation of web app shortcuts or manifest files following visits to low-reputation domains.
  • Retain browser process telemetry, file creation events, and URL history to support post-incident review.

How to Mitigate CVE-2026-14122

Immediate Actions Required

  • Update Google Chrome on all Windows endpoints to version 150.0.7871.47 or later.
  • Force-restart Chrome after update deployment to ensure the patched binary is loaded into memory.
  • Verify patch adoption by auditing chrome://version output or Chrome Enterprise reporting.

Patch Information

Google addressed CVE-2026-14122 in the Stable Channel release documented in the Google Chrome Stable Update. Administrators should deploy Chrome 150.0.7871.47 or newer through Chrome Enterprise, Group Policy, or their standard software distribution channel. Additional maintainer context is available in the Chromium Issue Tracker Entry.

Workarounds

  • Restrict installation of web apps using the WebAppInstallForceList and DefaultWebAppInstallForceList Chrome enterprise policies until patched.
  • Disable installation prompts for untrusted sites by configuring WebAppSettings to block installs by default.
  • Advise users to avoid installing web apps from unknown sources and to close install prompts from unfamiliar sites.
bash
# Chrome Enterprise policy example (Windows registry)
# Block web app installations from unmanaged sources until patched
reg add "HKLM\Software\Policies\Google\Chrome" /v WebAppInstallForceList /t REG_SZ /d "[]" /f
reg add "HKLM\Software\Policies\Google\Chrome\WebAppSettings" /v "*" /t REG_SZ /d "{\"manifest_id\":\"*\",\"run_on_os_login\":\"blocked\"}" /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.