Description
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)
Published: 2026-08-25
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Local authorization bypass via CustomTabs
Action: Immediate Patch
AI Analysis

Impact

An incorrect authorization check (CWE-863) in Chrome’s CustomTabs component permits a local attacker to bypass the web origin policy. A co‑installed malicious application can launch a CustomTab and access web content or data from origins that should remain isolated. Based on the description, it is inferred that this could enable disclosure or manipulation of sensitive information, though the exact extent depends on the malicious app’s capabilities.

Affected Systems

Google Chrome for Android versions prior to 152.0.7977.65. The issue is limited to Android devices that use the CustomTabs interface to launch web content.

Risk and Exploitability

The flaw requires a local attacker with the ability to install a co‑existing app that can register itself as a CustomTabs provider. With the EPSS score of <1% and the vulnerability not listed in CISA’s KEV catalog, malicious exploitation is currently unproven. The high CVSS score of 9.8 indicates a critical risk, yet the Chromium security severity is Low, suggesting that the potential for widespread impact is limited. Nonetheless, any user who installs or allows a suspicious app to register a CustomTabs service could be affected.

Generated by OpenCVE AI on August 26, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to version 152.0.7977.65 or later.
  • Uninstall or block any untrusted applications that register as CustomTabs providers.
  • Disable CustomTabs usage in apps that do not need it or enforce app sandboxing to prevent upward elevation.

Generated by OpenCVE AI on August 26, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass via CustomTabs in Chrome

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Authorization Bypass via CustomTabs in Chrome

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:06:04.534Z

Reserved: 2026-08-25T06:10:30.722Z

Link: CVE-2026-79152

cve-icon Vulnrichment

Updated: 2026-08-26T19:05:36.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:10.490

Modified: 2026-08-27T19:12:43.410

Link: CVE-2026-79152

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:15:04Z

Weaknesses