Executive brief
A vulnerability in Google Chrome for Android could allow a malicious website to gain unauthorized privileges on a user's device. By tricking a user into visiting a specially crafted webpage, an attacker could exploit the browser's Near Field Communication (NFC) implementation to perform actions beyond normal security restrictions. This could potentially lead to unauthorized access to device features or data.
Technical details
An inappropriate implementation vulnerability exists in the Near Field Communication (NFC) component of Google Chrome for Android. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform privilege escalation within the context of the browser. The vulnerability was addressed in Chrome version 149.0.7827.53. While specific root cause details are restricted, the attack vector is network-based and requires user interaction (visiting a malicious site).
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published to NVD