Description
Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Browser
AI Analysis

Impact

The vulnerability in Google Chrome on Android allows an attacker with social engineering capabilities to manipulate the user interface and bypass system access restrictions, effectively elevating privileges. This is achieved through incorrect authorization handling that does not verify the source of UI interactions. The compromised user may experience unauthorized actions triggered by the attacker, such as executing privileged commands or accessing sensitive data.

Affected Systems

Google Chrome running on Android devices with versions earlier than 152.0.7977.65 is impacted. No other vendors or product variations are listed.

Risk and Exploitability

Chromium classifies the issue as low severity with a CVSS score of 4.3, and an EPSS score of <1% is available, indicating a low exploitation probability. The lack of a CISA KEV listing further suggests that the vulnerability is not actively exploited in the wild. The attack requires a social engineering component, meaning it relies on user interaction; therefore, the risk is mitigated only when users remain vigilant, but any user who falls for the social engineering vector could be compromised.

Generated by OpenCVE AI on August 26, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update on all Android devices to eliminate the authorization flaw
  • Ensure that devices are enrolled in an official update channel so that security patches are applied automatically
  • Educate users about the risks of interacting with unsolicited prompts or unexpected UI elements to reduce the effectiveness of social engineering attempts

Generated by OpenCVE AI on August 26, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Wed, 26 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Inadequate Authorization in Chrome Android Enables Social Engineering to Bypass System Restrictions

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Inadequate Authorization in Chrome Android Enables Social Engineering to Bypass System Restrictions

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Browser in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via UI Interaction. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:09:12.176Z

Reserved: 2026-08-25T06:12:00.566Z

Link: CVE-2026-79225

cve-icon Vulnrichment

Updated: 2026-08-26T19:08:16.362Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:16.640

Modified: 2026-08-27T13:41:57.293

Link: CVE-2026-79225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:00:04Z

Weaknesses