Executive brief
A security vulnerability exists in Google Chrome for Android's CustomTabs feature, which allows apps to open web content within the app. A local attacker could use a specially crafted malicious file to gain elevated privileges on the device. This could allow an unauthorized application to perform actions or access data it should not normally be able to reach.
Technical details
An improper input validation vulnerability (CWE-20) exists in the CustomTabs component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when handling specific files. A local attacker can exploit this by providing a malicious file to the application, leading to privilege escalation. The vulnerability is addressed in version 150.0.7871.47. Access to specific bug details remains restricted by the Chromium team until a majority of users are updated.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched