Description
Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Now
AI Analysis

Impact

Missing authorization in Chrome CustomTabs on Android devices that run a version earlier than 152.0.7977.65 can let a local attacker gain control beyond the sandbox of the Chrome application. The flaw allows a co‑installed app that is able to open CustomTabs to run arbitrary code on the device, potentially affecting all data and system components. This is identified as a CWE‑862 vulnerability, indicating a failure to enforce proper authorization checks.

Affected Systems

The affected product is Google Chrome for Android; the vulnerability exists only in releases prior to 152.0.7977.65. Any device that has Chrome installed from a channel older than this build and that receives CustomTabs requests from other locally installed applications is at risk.

Risk and Exploitability

The vulnerability does not appear in the CISA KEV catalog and the EPSS score is < 1%, indicating a very low but non‑zero likelihood of exploitation. The Chromium classification as medium severity combined with a CVSS score of 7.4 suggests a moderate risk level. The attack vector requires the attacker to be in physical or local administrative control of an Android device and to have a co‑installed application capable of opening CustomTabs. If exploited, the flaw would allow bypassing the Chrome sandbox boundaries, enabling execution of code at a privilege level equal to or greater than Chrome, potentially affecting all data and system components.

Generated by OpenCVE AI on August 26, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later on all Android devices
  • Verify that no untrusted or malicious applications can invoke CustomTabs; consider disabling or uninstalling such apps
  • Maintain the device operating system and other applications at their latest security updates to reduce the potential attack surface

Generated by OpenCVE AI on August 26, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Missing Authorization in Chrome CustomTabs

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Missing Authorization in Chrome CustomTabs

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:17.599Z

Reserved: 2026-08-25T06:13:11.681Z

Link: CVE-2026-79286

cve-icon Vulnrichment

Updated: 2026-08-26T16:42:51.228Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:22.747

Modified: 2026-08-27T04:17:58.997

Link: CVE-2026-79286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:00:12Z

Weaknesses