Executive brief
Google Chrome on Android contains a flaw in its CustomTabs feature that allows a malicious app installed on the same device to read sensitive information from other apps' web sessions. An attacker would need to have an app already installed alongside Chrome to exploit this, but once in place, they can bypass normal security barriers that prevent apps from accessing each other's data, potentially stealing login credentials, personal information, or other sensitive content.
Technical details
An observable discrepancy vulnerability in the CustomTabs component of Google Chrome on Android (prior to version 152.0.7977.65) permits local attackers to obtain cross-origin data via a co-installed app. The vulnerability is classified as an information disclosure flaw and requires local access—specifically, another app already installed on the device. The attack leverages the CustomTabs API's handling of cross-origin requests to leak data that should be isolated between web contexts. An attacker with a malicious co-installed application can exploit this to read cross-origin data from legitimate web applications. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 and later