Executive brief
A security issue in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs through the CustomTabs feature, which apps use to display web content. An attacker could use a specially crafted webpage to bypass security boundaries and potentially leak sensitive user information.
Technical details
A vulnerability exists in the CustomTabs component of Google Chrome for Android due to insufficient policy enforcement. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak data from different origins. The issue is fixed in version 149.0.7827.53. The vulnerability is categorized by Chromium as Low severity.
Affected products
- Google Chrome for Android prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-05: disclosed: NVD publication date