webapk spoofing

  1. CVE-2026-11127: Chrome for Android WebAPK Domain Spoofing (Patch to 149.0.7827.53)

    Google disclosed CVE-2026-11127 on June 4, 2026, as a medium-severity Chrome for Android flaw in WebAPKs that affected versions before 149.0.7827.53 and could let a remote attacker spoof a domain through a crafted WebAPK. The bug is not the scariest item in Chrome 149’s unusually large security...