Description
Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome for Android’s NFC handling permits a remote attacker to read data from a rendered HTML page; the vulnerability arises from improper validation of NFC data and insufficient origin checks, enabling cross‑origin information exposure. Based on the description, it is inferred that the attacker must first compromise the renderer process before exploiting this NFC flaw, as the attack path requires the renderer to be already compromised. Once the renderer is compromised, the attacker can leak potentially sensitive data from other web origins, which may affect confidentiality of user data that is normally protected by the same‑origin policy.

Affected Systems

All Android devices running Google Chrome stable channel version 150.0.7871.47 or earlier are affected if they have not applied the recent update. The issue applies to every instance of Chrome on those devices that has not yet been patched to the fixed release.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low current likelihood that exploitation will occur. Because the attack requires an initial compromise of the renderer—typically via a separate vulnerability—the overall risk remains moderate. The vulnerability is not listed in the CISA KEV catalog, further suggesting that it is not widely exploited at present. Nonetheless, a successful attacker who gains renderer access could obtain cross‑origin data that would otherwise be unavailable.

Generated by OpenCVE AI on July 16, 2026 at 12:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later, which removes the incorrect NFC data handling logic.
  • If upgrading is not immediately possible, disable NFC functionality in Chrome via device‑wide policies or by blocking the NFCMonitor component to remove the attack surface.
  • Implement additional isolation for renderer processes so that, in the event of a compromise, cross‑origin data cannot be read via NFC; for example, enforce stricter origin checks or apply sandboxing policies that restrict renderer access to NFC data.

Generated by OpenCVE AI on July 16, 2026 at 12:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android NFC Cross‑Origin Data Leak via Compromised Renderer

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android NFC Cross‑Origin Data Leak via Compromised Renderer

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Cross‑Origin Data Leakage

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Cross‑Origin Data Leakage

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via NFC in Chrome Android Prior to 150.0.7871.47

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via NFC in Chrome Android Prior to 150.0.7871.47

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Chrome NFC Handling Vulnerability Enables Cross‑Origin Data Leak via Mal

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome NFC Handling Vulnerability Enables Cross‑Origin Data Leak via Mal

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title NFC Vulnerability Enables Cross-Origin Data Leaks in Chrome Android

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title NFC Vulnerability Enables Cross-Origin Data Leaks in Chrome Android

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title NFC Cross‑Origin Data Leak via Renderer Compromise

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title NFC Cross‑Origin Data Leak via Renderer Compromise

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Vulnerability Enables Cross‑Origin Data Leak

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Vulnerability Enables Cross‑Origin Data Leak

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title NFC Data Leakage in Chrome on Android via Renderer Compromise

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title NFC Data Leakage in Chrome on Android via Renderer Compromise

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Inappropriate NFC Implementation Allows Cross‑Origin Data Leakage in Chrome for Android

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Inappropriate NFC Implementation Allows Cross‑Origin Data Leakage in Chrome for Android

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via NFC Handler in Google Chrome for Android

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
CWE-352
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via NFC Handler in Google Chrome for Android
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Compromise Allows Cross‑Origin Data Leakage in Chrome Android
Weaknesses CWE-200

Wed, 01 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Compromise Allows Cross‑Origin Data Leakage in Chrome Android
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:22:01.289Z

Reserved: 2026-06-29T23:03:42.521Z

Link: CVE-2026-13887

cve-icon Vulnrichment

Updated: 2026-07-01T15:21:56.339Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:45:05Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-352

    Cross-Site Request Forgery (CSRF)