CVE-2026-3935
vulnerability analysis and mitigation

Overview

CVE-2026-3935 is an incorrect security UI vulnerability in the WebAppInstalls component of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by Barath Stalin K on January 28, 2026, and publicly disclosed on March 10, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects all versions of Google Chrome prior to 146.0.7680.71 on Windows, Mac, and Linux. It carries a CVSS v3.1 base score of 6.5 (Medium) and is rated Medium severity by the Chromium security team (Chrome Releases, Feedly).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where Chrome's WebAppInstalls feature fails to correctly render security-relevant UI elements when processing certain HTML content. An attacker can craft a malicious HTML page that manipulates how Chrome displays web app installation prompts or security dialogs, causing the browser to present misleading or spoofed UI to the user. Exploitation requires no privileges and no special configuration, but does require user interaction — specifically, a victim must visit the attacker-controlled page. The Chromium bug tracker entry is issue #479326680, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases).

Impact

Successful exploitation primarily affects integrity, as an attacker can deceive users into believing they are interacting with legitimate Chrome installation interfaces or security dialogs. This could lead users to approve malicious web app installations, grant unintended permissions, or take other actions under false pretenses. There is no direct confidentiality or availability impact from this vulnerability alone, but the social engineering potential could facilitate follow-on attacks (Feedly).

Exploitation steps

  1. Craft malicious HTML page: An attacker creates a specially crafted HTML page that triggers Chrome's WebAppInstalls UI flow in a way that misrepresents security-critical information — for example, displaying a fake or misleading web app installation prompt.
  2. Deliver to victim: The attacker distributes the malicious URL via phishing email, social media, or a compromised/malicious website to lure a target Chrome user into visiting the page.
  3. Trigger UI spoofing: When the victim loads the page in a vulnerable Chrome version (prior to 146.0.7680.71), the incorrect security UI is rendered, presenting a spoofed installation dialog or security prompt.
  4. Deceive user into action: The victim, believing the dialog is legitimate, approves a web app installation or grants permissions, potentially enabling further attacker-controlled behavior such as installing a malicious PWA or granting site permissions (Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026. Users and administrators should update Google Chrome to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).

Community reactions

GBHackers covered the Chrome 146 update, noting it addressed 29 vulnerabilities including CVE-2026-3935. Palo Alto Networks issued a security advisory (PAN-SA-2026-0004) referencing the Chromium monthly vulnerability update for April 2026, which includes this CVE. Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own security advisories and package updates to address the vulnerability in their Chromium packages (GBHackers, Palo Alto Networks).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management