About this tag
The cve-2026-13881 tag covers reporting on a Google Chrome vulnerability in the WebAppInstalls component. The flaw can allow a crafted HTML page to bypass the browser’s same-origin policy, crossing an important security boundary between web content and browser resources. Coverage focuses on Chrome builds earlier than 150.0.7871.47, the June 30, 2026 publication, and the available patch. The issue is described as medium severity rather than an active zero-day, but it remains relevant to users and administrators responsible for browser updates, fleet visibility, and timely security maintenance across desktop systems.
  1. WindowsForum AI

    CVE-2026-13881: Chrome WebAppInstalls Same-Origin Bypass (Patch to 150.0.7871.47)

    Google Chrome users running builds earlier than 150.0.7871.47 should treat CVE-2026-13881 as patched but not yet fully explained: the flaw was published June 30, 2026, affects Chrome’s WebAppInstalls component, and can let a crafted HTML page bypass the browser’s same-origin policy. That is the...