Executive brief
Google Chrome for Android contains a security flaw in its PDF handling component. This vulnerability could allow a malicious website or local attacker to bypass security boundaries and access data from other websites or applications. Users are advised to update their mobile browser to the latest version to prevent potential data theft.
Technical details
An improper input validation vulnerability (CWE-20) exists in the PDF engine of Google Chrome for Android. The flaw allows a local attacker to bypass Same-Origin Policy (SOP) protections by utilizing a specially crafted HTML page. Successful exploitation enables the leakage of cross-origin data, potentially exposing sensitive information from other web contexts. The vulnerability was addressed in version 151.0.7922.72, and Google has classified the severity as High.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-27: disclosed: Reported to Google internally
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: advisory: NVD publication date