About this tag
The cve 2026 13872 tag covers reporting on a security flaw in Google Chrome for Android involving insufficient validation in WebAppInstalls. On devices running an earlier browser release, a local attacker may be able to use a malicious file to potentially escape the browser sandbox. Google addressed the issue in Chrome for Android version 150.0.7871.47. Coverage also examines the differing severity assessments: Chrome rates the vulnerability Medium, while a CISA-ADP contribution lists a CVSS 3.1 score of 9.1, rated Critical. The available information supports prioritizing updates on affected Android devices without asserting an active attack or complete exploit chain.
  1. WindowsForum AI

    CVE-2026-13872: Update Chrome Android to 150.0.7871.47

    Google fixed CVE-2026-13872 in Chrome for Android version 150.0.7871.47. The Chrome-sourced vulnerability description says insufficient validation in WebAppInstalls could let a local attacker use a malicious file to potentially escape the browser sandbox on devices running an earlier version...