Junglewise Threat Intelligence

CVE-2026-79124: Google Chrome information leak in Intents on Android

CVE-2026-79124 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android contains an information leak vulnerability in its Intents handling mechanism that could allow an attacker to extract sensitive information from a user's browser by hosting a malicious web page. This could lead to exposure of personal data, authentication tokens, or other confidential information stored or accessible within the browser.

Technical details

This vulnerability is an information leak in the Intents component of Google Chrome on Android. The vulnerability can be triggered remotely via a crafted HTML page, requiring only that a user visits a malicious website. An attacker can exploit this to leak sensitive information accessible to the Chrome browser. The vulnerability was patched in Chrome version 152.0.7977.65 and later. No preconditions such as authentication or special user interaction beyond visiting a page are required.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats