Executive brief
Google Chrome on Android includes a feature called CustomTabs that allows third-party apps to embed browser functionality. A flaw in this feature allows a malicious app installed on the same device to bypass web origin security policies and access content that should be restricted to other apps. An attacker with a co-installed app could exploit this to steal data or impersonate trusted websites.
Technical details
The vulnerability is an incorrect authorization issue in Chrome's CustomTabs implementation on Android prior to version 152.0.7977.65. CustomTabs is a Chrome API that allows third-party applications to integrate a Chrome browsing session. The flaw permits a local attacker with a co-installed malicious app to bypass web origin policy restrictions, enabling unauthorized access to content from other origins. The attack requires a co-installed app on the same device and does not require network-based exploitation. Chrome 152.0.7977.65 and later versions contain the fix for this vulnerability.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 or later