Junglewise Threat Intelligence

CVE-2026-11247: Google Chrome for Android cross-origin data leak in CustomTabs

CVE-2026-11247 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome for Android, Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs through the CustomTabs feature, which apps use to display web content. An attacker could use a specially crafted webpage to bypass security boundaries and potentially leak sensitive user information.

Technical details

A vulnerability exists in the CustomTabs component of Google Chrome for Android due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak data from different origins. The issue is fixed in version 149.0.7827.53. The vulnerability is categorized by Chromium as Low severity.

Affected products

  • Google Chrome for Android prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-05: disclosed: NVD publication date

References

Related threats