CVE-2026-11008 | Google Chrome up to 148.0.7778.216 WebAppInstalls cross-domain policy (ID 495864 / Nessus ID 319287)
A vulnerability was found in Google Chrome. It has been classified as problematic. Affected by this issue is some unknown functionality of the component WebAppInstalls. This manipulation causes permissive cross-domain policy with untrusted domains.
This vulnerability is handled as CVE-2026-11008. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.