Executive brief
Google Chrome's CustomTabs feature on Android failed to properly authorize access to sensitive user information. A locally installed malicious app could exploit this flaw to read sensitive data from Chrome without explicit user permission, compromising browser privacy and user data security.
Technical details
This is a missing authorization vulnerability in CustomTabs, a Chrome feature that allows third-party apps to embed Chrome functionality. The vulnerability exists prior to version 152.0.7977.65 on Android. An attacker with a co-installed app on the same device can exploit the authorization bypass to access sensitive information. The attack requires local access and does not require remote network connectivity. Google patched this issue in Chrome 152.0.7977.65 for Android.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Android