Description
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Update
AI Analysis

Impact

A local attacker can use a co‑installed app to read cross‑origin data from Google Chrome on Android by exploiting an observable discrepancy in CustomTabs. This flaw permits the attacker to extract data that should be isolated to another origin, effectively leaking sensitive information. The weakness is governed by CWE‑203, which describes improper restriction of information disclosure.

Affected Systems

Google Chrome for Android versions before 152.0.7977.65 are affected. The issue arises in the CustomTabs functionality used by local applications to embed web content within Chrome.

Risk and Exploitability

The vulnerability requires local access to the device and a malicious co‑installed application; it does not allow remote code execution or privilege escalation. The CVSS score of 2.9 indicates a Low severity, while the EPSS score is less than 1%, showing a very low probability of exploitation. The vector is local, so an attacker must already have the ability to install or run apps on the device, but once that condition is met, sensitive data can be obtained unobtrusively.

Generated by OpenCVE AI on August 28, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later, which removes the CustomTabs discrepancy.
  • Limit the installation of unknown or untrusted third‑party applications that could exploit CustomTabs.
  • Verify that the device’s operating system and security settings are current and that the Chrome app has the minimum necessary permissions configured.

Generated by OpenCVE AI on August 28, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Fri, 28 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Disclosure via CustomTabs in Google Chrome for Android

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Tue, 25 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:37:13.002Z

Reserved: 2026-08-25T06:04:12.296Z

Link: CVE-2026-78936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:49.383

Modified: 2026-08-31T18:57:39.223

Link: CVE-2026-78936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:00:14Z

Weaknesses