Name CVE-2026-10923 Description Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High) Source CVE (at NVD ; CERT , ENISA , LWN , oss-sec , fulldisc , Debian ELTS , Red Hat , Ubuntu , Gentoo , SUSE bugzilla /CVE , GitHub advisories /code /issues , web search , more )References DSA-6325-1
Vulnerable and fixed packages The table below lists information on source packages.
Source Package Release Version Status chromium (PTS )bullseye (security), bullseye 120.0.6099.224-1~deb11u1 vulnerable bookworm 147.0.7727.137-1~deb12u1 vulnerable bookworm (security) 149.0.7827.102-1~deb12u1 fixed trixie 147.0.7727.137-1~deb13u1 vulnerable trixie (security) 149.0.7827.102-1~deb13u1 fixed forky 148.0.7778.178-1 vulnerable sid 149.0.7827.102-1 fixed
The information below is based on the following data on fixed versions.
Notes [bullseye] - chromium <end-of-life> (see #1061268)