Junglewise Threat Intelligence

CVE-2026-11035: Google Chrome for Android privilege escalation in Custom Tabs

CVE-2026-11035 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome for Android. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a local attacker to gain elevated privileges on a device. This issue occurs within the Custom Tabs feature, which apps use to display web content. An attacker could exploit this by using a specially crafted file to bypass security boundaries, potentially compromising user data or device operations.

Technical details

A privilege escalation vulnerability exists in Google Chrome for Android's Custom Tabs component due to an inappropriate implementation of input handling. The flaw, classified as improper input validation (CWE-20), allows a local attacker to trigger elevated permissions by providing a specially crafted XML file. The vulnerability was addressed in version 149.0.7827.53. While the specific mechanism of the escalation is restricted, it typically involves bypassing Android's Intent or permission model through the browser's interface with other applications.

Affected products

  • Google Chrome for Android prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats