Description
Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑origin data leakage via CustomTabs
Action: Immediate Update
AI Analysis

Impact

An observable discrepancy in CustomTabs on Google Chrome for Android, present in versions prior to 152.0.7977.65, allows a local attacker to obtain data from different origins through a co‑installed application. This flaw is classified as CWE‑203, indicating that information is improperly exposed to an attacker. The vulnerability can result in a confidentiality breach for data accessed through CustomTabs, with no denial of service or privilege escalation described.

Affected Systems

Google Chrome on Android, all versions before 152.0.7977.65. The affected systems include devices running any pre‑65 build of the Chrome stable channel on Android, with version numbers such as 152.0.0–151.x. No specific sub‑versions are listed beyond the upper bound.

Risk and Exploitability

Chromium rates this bug as medium severity, with a CVSS score of 2.9. The vulnerability requires a local malicious application that co‑installs with Chrome, allowing the attacker to access cross‑origin data. The attack vector is local and no remote exploitation pathway is described in the CVE data. The EPSS score of <1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 28, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or later on all Android devices.
  • If an immediate update is not possible, remove or change the default handling of CustomTabs for any third‑party applications that open Chrome via CustomTabs (via Settings ► Apps ► [app] ► Open by default ► clear defaults).
  • Enforce Chrome updates through device management or MDM policies to ensure all devices receive future security patches promptly.

Generated by OpenCVE AI on August 28, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Fri, 28 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title CustomTabs Cross‑Origin Data Leakage in Google Chrome for Android

Fri, 28 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title CustomTabs Cross‑Origin Data Leakage in Google Chrome for Android

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Observable discrepancy in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain cross-origin data via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-203
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T18:37:51.222Z

Reserved: 2026-08-25T06:04:35.845Z

Link: CVE-2026-78949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:50.853

Modified: 2026-08-31T18:58:30.873

Link: CVE-2026-78949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T23:15:04Z

Weaknesses