Executive brief
A vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites you have visited. This occurs due to a flaw in how the browser handles file selection inputs. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information.
Technical details
An improper input validation vulnerability (CWE-20) exists in the File Input component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker using a crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other origins. The vulnerability is addressed in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-10: disclosed: Reported to Chromium by Google researchers
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory