Executive brief
Google Chrome on Android contains an information leak vulnerability in its Intents handling mechanism that could allow an attacker to extract sensitive information from a user's browser by hosting a malicious web page. This could lead to exposure of personal data, authentication tokens, or other confidential information stored or accessible within the browser.
Technical details
This vulnerability is an information leak in the Intents component of Google Chrome on Android. The vulnerability can be triggered remotely via a crafted HTML page, requiring only that a user visits a malicious website. An attacker can exploit this to leak sensitive information accessible to the Chrome browser. The vulnerability was patched in Chrome version 152.0.7977.65 and later. No preconditions such as authentication or special user interaction beyond visiting a page are required.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65