
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11127 is a domain spoofing vulnerability caused by an inappropriate implementation in the WebAPKs component of Google Chrome on Android. It allows a remote attacker to spoof the domain of a legitimate website by delivering a crafted WebAPK package to a victim. The vulnerability affects all versions of Google Chrome on Android prior to 149.0.7827.53, and was reported internally by Google on April 10, 2026. It was publicly disclosed on June 4, 2026, as part of the Chrome 149 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Advisory, Feedly).
The root cause is classified as CWE-358 (Improperly Implemented Security Check for Standard), meaning Chrome's WebAPK subsystem on Android fails to properly enforce domain/origin validation when processing WebAPK packages. WebAPKs are Android APK files generated by Chrome to enable Progressive Web Apps (PWAs) to be installed on Android devices; they embed the app's scope and start URL. The flaw allows an attacker to craft a malicious WebAPK that misrepresents its associated domain, causing Chrome to display an incorrect origin to the user. Exploitation requires user interaction — specifically, the victim must install or interact with the crafted WebAPK — and no authentication or special privileges are required of the attacker (Chrome Advisory, Feedly).
Successful exploitation allows an unauthenticated remote attacker to deceive Android users about the true origin of web content they are viewing, effectively impersonating a legitimate website or web application. The primary impact is on integrity (CVSS integrity impact: High), as users may be misled into submitting credentials, sensitive data, or performing actions they believe are directed at a trusted domain. There is no direct confidentiality or availability impact, but the spoofing capability could facilitate phishing, credential harvesting, or social engineering attacks against Chrome for Android users (Feedly, Chrome Advisory).
Google has addressed this vulnerability in Chrome 149.0.7827.53 for Android (and 149.0.7827.53/54 for Windows/Mac/Linux). Users should update Google Chrome on Android to version 149.0.7827.53 or later via the Google Play Store. As a precautionary measure, users should avoid installing WebAPKs from untrusted or unknown sources and verify the legitimacy of any PWA installation prompt. No configuration-based workaround has been published; updating to the patched version is the recommended remediation (Chrome Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."