Executive brief
Google Chrome for Android contains an information leak in its Sharing feature that allows a local attacker to obtain sensitive information through a co-installed app. An attacker would need to use social engineering to trick a user into triggering the share functionality. This vulnerability could lead to exposure of user data depending on what information is being shared.
Technical details
This vulnerability is an information leak (CWE-200 or similar) in Google Chrome's Sharing component on Android, affecting versions prior to 152.0.7977.65. The attack is local in nature, requiring an attacker to leverage a co-installed application on the same device combined with social engineering. An attacker cannot exploit this remotely; they must first establish a local presence on the device via a co-installed app, then manipulate user behavior to trigger the vulnerable share operation. The vulnerability allows the attacker to read sensitive information that should not be accessible. Google has patched this issue in Chrome 152.0.7977.65 or later.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65