Description
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization check in the CustomTabs component of Google Chrome on Android, allowing a local attacker to bypass the browser’s web origin policy via a co‑installed application. This flaw is identified as a missing authorization for an existing resource (CWE‑863). The result is that a malicious package installed alongside Chrome can access content that should be restricted by the browser’s origin boundaries, potentially exposing confidential data or enabling further compromise of the device.

Affected Systems

Google Chrome for Android versions older than 152.0.7977.65 are affected. Users of these builds on any Android device run the risk of exploitation by a local application bundled with or placed in the same user space as Chrome.

Risk and Exploitability

The flaw requires local execution of a co‑installed app, so the attacker must already have a package installed on the device. The EPSS score of 0.00168 indicates a very low but non‑zero probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, and the CVSS score of 4.3 indicates moderate severity. Nonetheless, because it breaches web origin separation, it poses a significant confidentiality risk. An update that adds the missing authorization check mitigates the issue.

Generated by OpenCVE AI on August 28, 2026 at 19:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later to include the authorization fix.
  • Ensure the device runs the latest stable Chrome build by configuring automatic updates or manually checking for updates.
  • Restrict the installation of unknown co‑installed applications or use a device‑management policy that blocks apps from leveraging Chrome’s CustomTabs.

Generated by OpenCVE AI on August 28, 2026 at 19:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome CustomTabs Authorization Bypass on Android

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome CustomTabs Authorization Bypass on Android

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to bypass web origin policy via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T20:37:08.396Z

Reserved: 2026-08-25T06:11:53.085Z

Link: CVE-2026-79222

cve-icon Vulnrichment

Updated: 2026-08-27T20:32:27.503Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:16.307

Modified: 2026-08-28T14:35:33.707

Link: CVE-2026-79222

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:00:16Z

Weaknesses