Executive brief
Google Chrome's CustomTabs feature on Android contains a flaw that allows a locally installed malicious app to read sensitive data from other apps through information leakage. An attacker with access to the device could exploit this to steal cross-origin data, compromising user privacy without requiring elevated permissions or user interaction beyond app installation.
Technical details
The vulnerability is an observable discrepancy (information disclosure) in Chrome's CustomTabs implementation on Android prior to version 152.0.7977.65. The flaw allows a local attacker running a co-installed application to obtain cross-origin data through side-channel observation or timing attacks. The attack requires local code execution (a separate app installed on the same device) but no user interaction beyond normal app usage. An attacker can leverage this to exfiltrate sensitive browsing data or information from other applications. The issue is fixed in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65