Description
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Sensitive Data Leak
Action: Apply Update
AI Analysis

Impact

A missing authorization check in Chrome's CustomTabs on Android allows a local attacker who has co‑installed an app with Chrome to access sensitive data that should be protected by Chrome's user context. This flaw is classified under CWE‑862 and can lead to the disclosure of confidential information. The vulnerability is not a remote exploit; it requires local or co‑installed application privileges, but it still compromises data integrity and confidentiality within the device. The security severity is medium as noted by Chromium.

Affected Systems

The affected vendor is Google; the product is Chrome for Android. Any device running Chrome versions prior to 152.0.7977.65 is vulnerable when CustomTabs is enabled and an attacker can install a companion app on the device.

Risk and Exploitability

The exploitation requires local installation of a malicious or compromised app, so the risk is limited to users who install such apps on a device with an outdated Chrome. The CVSS score is 5.1, the EPSS score is < 1%, and the vulnerability has not been listed in the CISA KEV catalog, indicating no known widespread exploitation at the time of analysis. However, because the flaw permits sensitive data leakage without proper authorization, administrators should prioritize updating Chrome to the latest stable release or disabling CustomTabs until a patch is applied.

Generated by OpenCVE AI on August 26, 2026 at 22:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later
  • Disable CustomTabs usage in Chrome settings if the feature is not required
  • Restrict installation of unknown or untrusted applications on the device and monitor for recent installations

Generated by OpenCVE AI on August 26, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Wed, 26 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Local Sensitive Data Leak through CustomTabs in Google Chrome (Android)

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Local Sensitive Data Leak through CustomTabs in Google Chrome (Android)

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:43:31.000Z

Reserved: 2026-08-25T06:08:57.413Z

Link: CVE-2026-79086

cve-icon Vulnrichment

Updated: 2026-08-26T18:11:35.488Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:04.200

Modified: 2026-08-28T17:30:40.143

Link: CVE-2026-79086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:15:05Z

Weaknesses