Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites you have open. This occurs due to a flaw in how the browser handles Near Field Communication (NFC) policies. While the risk is rated as low, an attacker could potentially leak sensitive information if a user visits a specially crafted web page.
Technical details
An insufficient policy enforcement vulnerability exists in the NFC component of Google Chrome for Android. The flaw allows a remote attacker to bypass cross-origin restrictions and leak data from different origins by enticing a user to visit a malicious HTML page. This is classified as a cross-origin data leak. The vulnerability was addressed in version 151.0.7922.72. Access to specific bug details remains restricted by the Chromium team to allow users time to update.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date