Description
Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of system access restrictions via CustomTabs
Action: Assess Impact
AI Analysis

Impact

Google Chrome for Android contains a flaw in the CustomTabs component’s reference resolution logic that can be triggered by a crafted HTML page. The bug enables a remote attacker to cause the system to resolve references outside the intended scope, effectively bypassing built‑in access restrictions. This can let an attacker gain unauthorized access to other apps or system resources that should remain protected, potentially allowing the compromise of sensitive data or execution of privileged commands. The weakness is classified as a Reference Validation flaw, CWE-706.

Affected Systems

The vulnerability affects Chrome for Android versions earlier than 152.0.7977.65. Users running any unsupported older build are at risk until an updated release is installed.

Risk and Exploitability

The CVE has no public exploit score and is not listed in the CISA KEV catalog; the EPSS score is < 1%, indicating a very low probability of exploitation. Chromium security teams rate the issue as Low severity with a CVSS score of 4.3. The attack requires delivering a crafted HTML page that is opened in a CustomTabs session, which most likely implies user interaction or a malicious app distributing such content. Given the low severity and lack of a public exploit, the likelihood of exploitation is currently considered low, but the effect is high enough to warrant monitoring of affected devices.

Generated by OpenCVE AI on August 26, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or later on Android, which contains the patch for CustomTabs reference resolution
  • Configure applications to avoid exposing CustomTabs to untrusted content; use content‑security‑policy or restrict navigation to trusted URLs
  • If immediate updating is not possible, disable CustomTabs for sensitive applications or enforce stricter browser sandboxing to prevent untrusted references

Generated by OpenCVE AI on August 26, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Bypass System Access via CustomTabs Reference Resolution Vulnerability

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Bypass System Access via CustomTabs Reference Resolution Vulnerability

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:58:07.848Z

Reserved: 2026-08-25T06:12:39.625Z

Link: CVE-2026-79254

cve-icon Vulnrichment

Updated: 2026-08-26T18:58:03.219Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:19.883

Modified: 2026-08-27T13:38:51.467

Link: CVE-2026-79254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:15:04Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference