Executive brief
Google Chrome on Android is a mobile web browser used for accessing the internet. A security flaw in how the browser handles USB connections could allow a malicious website to access data from other websites if the browser's security layers have already been partially compromised. This could lead to the unauthorized exposure of sensitive user information across different web services.
Technical details
An insufficient policy enforcement vulnerability exists in the USB component of Google Chrome for Android. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass cross-origin restrictions. By enticing a user to visit a specially crafted HTML page, the attacker can leak data across origins. This vulnerability is mitigated by the requirement of a prior renderer compromise. Google has addressed this issue in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: disclosed: NVD publication date