Junglewise Threat Intelligence

CVE-2026-79152: Google Chrome CustomTabs authorization bypass on Android

CVE-2026-79152 · Severity: critical · CVSS 9.8 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's CustomTabs feature on Android contains an incorrect authorization flaw that allows a locally installed malicious app to bypass web origin security policies. An attacker with a co-installed app could access content or functionality that should be restricted to specific websites, potentially leading to credential theft, unauthorized data access, or session hijacking.

Technical details

This is an incorrect authorization vulnerability in the CustomTabs component of Google Chrome on Android (versions prior to 152.0.7977.65). The flaw allows a local attacker with a co-installed app to bypass web origin policy enforcement, which normally restricts what data and resources each website can access. The attack requires the presence of a malicious app already installed on the device (local attack vector). An attacker can exploit this to perform unauthorized actions within the context of trusted web origins. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats