Executive brief
A security issue in Google Chrome for Android could allow a malicious application or website on a user's device to access data from other websites. This occurs through the CustomTabs feature, which is used to display web content within other apps. An attacker could use a specially crafted web page to bypass security boundaries and leak sensitive information.
Technical details
A vulnerability classified as an inappropriate implementation exists in the CustomTabs component of Google Chrome for Android. The flaw allows a local attacker to bypass Same-Origin Policy (SOP) protections and leak cross-origin data. To exploit this, an attacker must entice a user to interact with a specially crafted HTML page. This could lead to the unauthorized disclosure of sensitive information from other web origins. The issue is addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-05: disclosed: NVD publication date