Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A security flaw in the browser's Near Field Communication (NFC) handling could allow a malicious website to access data from other websites that the user has open. This could lead to the unauthorized exposure of sensitive user information or browsing data.
Technical details
An information disclosure vulnerability exists in Google Chrome for Android due to insufficient policy enforcement within the NFC component. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak data from other origins. This issue was addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed