Executive brief
A security issue in Google Chrome for Android could allow a malicious website to bypass standard security boundaries. If a user is tricked into performing specific touch gestures or interactions on a specially crafted webpage, the attacker could potentially access data from other websites. This bypasses the 'Same Origin Policy,' which is a fundamental security feature designed to keep data from different websites isolated from one another.
Technical details
A vulnerability exists in the PreviewTab component of Google Chrome for Android due to insufficient policy enforcement. A remote attacker can exploit this by hosting a crafted HTML page and convincing a user to perform specific UI gestures. Successful exploitation allows the attacker to bypass the Same Origin Policy (SOP), potentially leading to unauthorized access to data across different web origins. The issue is addressed in Google Chrome version 149.0.7827.53. Chromium has rated this as a Low severity security issue.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel.
- 2026-06-04: disclosed: NVD publication date.