Junglewise Threat Intelligence

CVE-2026-13863: Google Chrome for Android privilege escalation in CustomTabs

CVE-2026-13863 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Android's CustomTabs feature, which allows apps to open web content within the app. A local attacker could use a specially crafted malicious file to gain elevated privileges on the device. This could allow an unauthorized application to perform actions or access data it should not normally be able to reach.

Technical details

An improper input validation vulnerability (CWE-20) exists in the CustomTabs component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when handling specific files. A local attacker can exploit this by providing a malicious file to the application, leading to privilege escalation. The vulnerability is addressed in version 150.0.7871.47. Access to specific bug details remains restricted by the Chromium team until a majority of users are updated.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats