Junglewise Threat Intelligence

CVE-2026-13887: Google Chrome for Android cross-origin data leak in NFC

CVE-2026-13887 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted page, potentially leading to the exposure of sensitive information across different web origins. Users should update their mobile browser to the latest version to mitigate this risk.

Technical details

An inappropriate implementation vulnerability exists in the Near Field Communication (NFC) component of Google Chrome for Android. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass cross-origin isolation. By enticing a user to visit a malicious HTML page, the attacker can leak sensitive data from other origins. This issue is addressed in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats