Description
Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome for Android contains an NFC handling issue that allows a remote attacker who has compromised the renderer process to leak cross‑origin data through a crafted HTML page. The flaw is rated moderate in severity as defined by Chromium security. This leak enables the attacker to read content that should be protected by the same‑origin policy, exposing user data or locally stored web content.

Affected Systems

Android devices running the Google Chrome stable channel with versions earlier than 150.0.7871.47 are vulnerable. The vulnerability applies to all Chrome installations on those devices until an update is applied.

Risk and Exploitability

A CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% implies a low likelihood of exploitation at present. The flaw requires the attacker to first gain control of a renderer process, which typically occurs via another vulnerability. Because the issue is not listed in the CISA KEV catalog, no widespread attacks have been reported. Nonetheless, with renderer compromise the attacker could retrieve cross‑origin data via a crafted page.

Generated by OpenCVE AI on August 4, 2026 at 08:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome 150.0.7871.47 or newer on all Android devices.
  • If a patch cannot be applied immediately, disable NFC usage in Chrome through device‑wide policies or Android settings to eliminate the attack vector.
  • Ensure that renderer processes are run with proper sandbox isolation; avoid running third‑party renderer processes without the default security controls.

Generated by OpenCVE AI on August 4, 2026 at 08:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 04 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title NFC Handling in Chrome on Android Enables Cross‑Origin Data Leak

Sun, 26 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leak via NFC in Chrome Android

Wed, 22 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leak via NFC in Chrome Android

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android NFC Cross‑Origin Data Leak via Compromised Renderer

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome for Android NFC Cross‑Origin Data Leak via Compromised Renderer

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Cross‑Origin Data Leakage

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Cross‑Origin Data Leakage

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via NFC in Chrome Android Prior to 150.0.7871.47

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via NFC in Chrome Android Prior to 150.0.7871.47

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Chrome NFC Handling Vulnerability Enables Cross‑Origin Data Leak via Mal

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome NFC Handling Vulnerability Enables Cross‑Origin Data Leak via Mal

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title NFC Vulnerability Enables Cross-Origin Data Leaks in Chrome Android

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title NFC Vulnerability Enables Cross-Origin Data Leaks in Chrome Android

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title NFC Cross‑Origin Data Leak via Renderer Compromise

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title NFC Cross‑Origin Data Leak via Renderer Compromise

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Vulnerability Enables Cross‑Origin Data Leak

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Android NFC Vulnerability Enables Cross‑Origin Data Leak

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title NFC Data Leakage in Chrome on Android via Renderer Compromise

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title NFC Data Leakage in Chrome on Android via Renderer Compromise

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Inappropriate NFC Implementation Allows Cross‑Origin Data Leakage in Chrome for Android

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Inappropriate NFC Implementation Allows Cross‑Origin Data Leakage in Chrome for Android

Wed, 01 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via NFC Handler in Google Chrome for Android

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
CWE-352
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via NFC Handler in Google Chrome for Android
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Compromise Allows Cross‑Origin Data Leakage in Chrome Android
Weaknesses CWE-200

Wed, 01 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Compromise Allows Cross‑Origin Data Leakage in Chrome Android
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T15:22:01.289Z

Reserved: 2026-06-29T23:03:42.521Z

Link: CVE-2026-13887

cve-icon Vulnrichment

Updated: 2026-07-01T15:21:56.339Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T23:17:02.950

Modified: 2026-07-06T14:56:30.720

Link: CVE-2026-13887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T08:15:06Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-352

    Cross-Site Request Forgery (CSRF)