Description
Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Update Chrome
AI Analysis

Impact

Google Chrome for Android contains a vulnerability that can cause sensitive information to be exposed to a co‑installed application. A local attacker with control over a second app can retrieve data that should remain private to Chrome. This flaw is classified as medium severity and illustrates the risk of local information leakage inherent in poorly isolated app environments.

Affected Systems

The issue affects Google Chrome Mobile on Android devices running a version older than 155.0.8059.39. Only browsers built with the affected code prior to this patch are vulnerable.

Risk and Exploitability

The vulnerability is exploitable from the local device, requiring the attacker to install or control a second application. No exploit probability score is available, and the flaw is not listed in CISA KEV. The medium CVSS rating underscores the potential impact of confidential data exposure, while the absence of a publicly known exploit limits immediate risk. Updating to the patched Chrome version mitigates the principal threat.

Generated by OpenCVE AI on October 6, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or later on all affected devices.
  • Remove or disable any co‑installed applications that are not from trusted sources or that may misuse Chrome’s data.
  • Restrict the permissions granted to installed apps, particularly those that can read data from the device’s application data store.
  • Keep the Android operating system and all security patches up to date to reduce the attack surface for local exploits.

Generated by OpenCVE AI on October 6, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Information Leak via Co‑installed App in Google Chrome Mobile

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Information leak in Mobile in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-200
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:21:20.783Z

Reserved: 2026-10-06T16:33:36.952Z

Link: CVE-2026-106254

cve-icon Vulnrichment

Updated: 2026-10-06T20:21:15.564Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:52.530

Modified: 2026-10-06T21:17:08.860

Link: CVE-2026-106254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor