Junglewise Threat Intelligence

CVE-2026-14046: Google Chrome for Android SOP bypass in CustomTabs

CVE-2026-14046 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to bypass standard security boundaries. Specifically, it affects CustomTabs, a feature that allows apps to open web content. If exploited, a malicious site could potentially access data from other websites that it should not be able to see, compromising user privacy.

Technical details

An inappropriate implementation vulnerability exists in the CustomTabs component of Google Chrome for Android. By convincing a user to visit a specially crafted HTML page, a remote attacker can bypass the Same-Origin Policy (SOP). This bypass could allow a malicious origin to interact with or access data from other origins within the CustomTabs context. The vulnerability is addressed in version 150.0.7871.47. Google classifies this with a 'Low' security severity.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats