Executive brief
Google Chrome on Android contains a security flaw in its CustomTabs feature, which allows apps to open web content within their own interface. A local attacker could use a specially crafted file to trick the browser into displaying misleading information or spoofing the user interface. This could be used to deceive users into performing unintended actions or trusting a malicious site.
Technical details
An improper input validation vulnerability (CWE-20) exists in the CustomTabs component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when processing files locally. A local attacker can exploit this by providing a malicious file that, when opened, causes the browser to display a spoofed user interface. This UI spoofing can be used to misrepresent the origin or content of a page to the user. The vulnerability is addressed in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory