Junglewise Threat Intelligence

CVE-2026-79146: Google Chrome information leak in CustomTabs on Android

CVE-2026-79146 · Severity: medium · CVSS 5.5 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome's CustomTabs feature on Android contained an information leak vulnerability that allowed a locally installed app to access cross-origin data from other applications. This could expose sensitive information from websites and apps a user visits without their knowledge or consent. The vulnerability affects Chrome versions prior to 152.0.7977.65 and has been patched in the latest release.

Technical details

The vulnerability is an information leak in Chrome's CustomTabs component on Android prior to version 152.0.7977.65. CustomTabs allows apps to display web content within a custom browser interface. The flaw permits a local attacker (via a co-installed malicious app) to obtain cross-origin data that should be isolated between applications. Attack requires local access to the device and a secondary malicious app installation, but no user interaction or special permissions. An attacker can extract sensitive data from browsing sessions. The vulnerability has been patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed

References

Related threats