Junglewise Threat Intelligence

CVE-2026-79222: Google Chrome incorrect authorization in CustomTabs on Android

CVE-2026-79222 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android includes a feature called CustomTabs that allows third-party apps to embed browser functionality. A flaw in this feature allows a malicious app installed on the same device to bypass web origin security policies and access content that should be restricted to other apps. An attacker with a co-installed app could exploit this to steal data or impersonate trusted websites.

Technical details

The vulnerability is an incorrect authorization issue in Chrome's CustomTabs implementation on Android prior to version 152.0.7977.65. CustomTabs is a Chrome API that allows third-party applications to integrate a Chrome browsing session. The flaw permits a local attacker with a co-installed malicious app to bypass web origin policy restrictions, enabling unauthorized access to content from other origins. The attack requires a co-installed app on the same device and does not require network-based exploitation. Chrome 152.0.7977.65 and later versions contain the fix for this vulnerability.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 or later

References

Related threats