Junglewise Threat Intelligence

CVE-2026-11278: Google Chrome for Android cross-origin data leak in CustomTabs

CVE-2026-11278 · Severity: info · CVSS 2 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious application or website on a user's device to access data from other websites. This occurs through the CustomTabs feature, which is used to display web content within other apps. An attacker could use a specially crafted web page to bypass security boundaries and leak sensitive information.

Technical details

A vulnerability classified as an inappropriate implementation exists in the CustomTabs component of Google Chrome for Android. The flaw allows a local attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit this, an attacker must entice a user to interact with a specially crafted HTML page. This could lead to the unauthorized disclosure of sensitive information from other web origins. The issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-05: disclosed: NVD publication date

References

Related threats