Executive brief
Google Chrome's CustomTabs feature on Android contains an incorrect authorization flaw that allows a locally installed malicious app to bypass web origin security policies. An attacker with a co-installed app could access content or functionality that should be restricted to specific websites, potentially leading to credential theft, unauthorized data access, or session hijacking.
Technical details
This is an incorrect authorization vulnerability in the CustomTabs component of Google Chrome on Android (versions prior to 152.0.7977.65). The flaw allows a local attacker with a co-installed app to bypass web origin policy enforcement, which normally restricts what data and resources each website can access. The attack requires the presence of a malicious app already installed on the device (local attack vector). An attacker can exploit this to perform unauthorized actions within the context of trusted web origins. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched