CVE-2026-11127
vulnerability analysis and mitigation

Overview

CVE-2026-11127 is a domain spoofing vulnerability caused by an inappropriate implementation in the WebAPKs component of Google Chrome on Android. It allows a remote attacker to spoof the domain of a legitimate website by delivering a crafted WebAPK package to a victim. The vulnerability affects all versions of Google Chrome on Android prior to 149.0.7827.53, and was reported internally by Google on April 10, 2026. It was publicly disclosed on June 4, 2026, as part of the Chrome 149 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Advisory, Feedly).

Technical details

The root cause is classified as CWE-358 (Improperly Implemented Security Check for Standard), meaning Chrome's WebAPK subsystem on Android fails to properly enforce domain/origin validation when processing WebAPK packages. WebAPKs are Android APK files generated by Chrome to enable Progressive Web Apps (PWAs) to be installed on Android devices; they embed the app's scope and start URL. The flaw allows an attacker to craft a malicious WebAPK that misrepresents its associated domain, causing Chrome to display an incorrect origin to the user. Exploitation requires user interaction — specifically, the victim must install or interact with the crafted WebAPK — and no authentication or special privileges are required of the attacker (Chrome Advisory, Feedly).

Impact

Successful exploitation allows an unauthenticated remote attacker to deceive Android users about the true origin of web content they are viewing, effectively impersonating a legitimate website or web application. The primary impact is on integrity (CVSS integrity impact: High), as users may be misled into submitting credentials, sensitive data, or performing actions they believe are directed at a trusted domain. There is no direct confidentiality or availability impact, but the spoofing capability could facilitate phishing, credential harvesting, or social engineering attacks against Chrome for Android users (Feedly, Chrome Advisory).

Exploitation steps

  1. Craft a malicious WebAPK: Create a WebAPK (Android APK) that embeds a manipulated manifest, associating the package with a spoofed domain (e.g., a trusted banking or email site) while the actual content is attacker-controlled.
  2. Distribute the WebAPK: Deliver the crafted WebAPK to the target via phishing email, malicious website, SMS, or social engineering — since WebAPKs are not distributed through the Play Store, users may be prompted to enable sideloading.
  3. Victim installs the WebAPK: The target Android user installs the malicious WebAPK on their device running a vulnerable version of Chrome (prior to 149.0.7827.53).
  4. Domain spoofing occurs: When the victim launches the installed app, Chrome displays the spoofed domain in the UI, making the user believe they are interacting with the legitimate website.
  5. Harvest credentials or data: The attacker's content, rendered under the guise of the spoofed domain, can be used to phish credentials, capture form submissions, or conduct further social engineering (Chrome Advisory, Feedly).

Indicators of compromise

  • File System: Presence of unexpected or unrecognized APK files on Android devices, particularly those not installed from the Google Play Store; WebAPK files with mismatched package names and displayed domain names.
  • Network: Outbound connections from a newly installed WebAPK to domains inconsistent with the app's displayed name or branding.
  • Logs: Android package manager logs showing installation of APKs from unknown sources around the time of suspected compromise; Chrome internal logs referencing WebAPK scope/origin mismatches.
  • Process/Behavior: Installed PWA/WebAPK apps on Android that display a well-known domain in the Chrome UI but connect to a different backend server (Feedly).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 149.0.7827.53 for Android (and 149.0.7827.53/54 for Windows/Mac/Linux). Users should update Google Chrome on Android to version 149.0.7827.53 or later via the Google Play Store. As a precautionary measure, users should avoid installing WebAPKs from untrusted or unknown sources and verify the legitimacy of any PWA installation prompt. No configuration-based workaround has been published; updating to the patched version is the recommended remediation (Chrome Advisory, Feedly).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management