Description
Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure on a local Android device
Action: Patch Chrome
AI Analysis

Impact

An incorrect authorization check in Google Chrome for Android enables an attacker who can co‑install an application and persuade a user to install it through social engineering to extract sensitive information from the browser. The flaw specifically allows the co‑installed app to bypass normal permission boundaries and read data that should be restricted to the browser process. This represents a medium‑severity source code issue identified as CWE‑863.

Affected Systems

The vulnerability exists in Google Chrome for Android versions earlier than 155.0.8059.39 and affects all devices that use these legacy releases. Users of older Chrome releases deployed on Android should consider this product impacted until they upgrade to a patched version.

Risk and Exploitability

The CVE is not listed in the CISA KEV catalog, and no EPSS score is available, which suggests limited publicly available exploitation data at this time. The CVSS base score of 5.1 indicates medium severity. Despite that, the potential for local privilege escalation via a co‑installed app is non‑trivial, especially in environments where users readily install unknown applications. The medium severity rating indicates a noticeable impact if exploited but not a critical or immediate denial of service. Patch status and user behavior remain the key determinants of risk.

Generated by OpenCVE AI on October 7, 2026 at 02:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 155.0.8059.39 or later using the Google Play Store or the Chrome built‑in updater.
  • Ensure the browser update is obtained from a trusted source such as the official stable channel or OTA update.
  • Avoid installing unknown co‑installed applications and review app permissions carefully before installation.

Generated by OpenCVE AI on October 7, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android Authorization Bypass via Co‑installed Application

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Browser in Google Chrome on on Android prior to 155.0.8059.39 allowed a local attacker leveraging social engineering to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:22:52.742Z

Reserved: 2026-10-06T16:34:59.493Z

Link: CVE-2026-106313

cve-icon Vulnrichment

Updated: 2026-10-06T20:22:45.918Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:59.570

Modified: 2026-10-07T13:42:23.890

Link: CVE-2026-106313

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses