Junglewise Threat Intelligence

CVE-2026-79225: Google Chrome incorrect authorization in Browser on Android

CVE-2026-79225 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome is a web browser used by millions of users to access the internet on Android devices. This vulnerability allows a remote attacker to bypass security restrictions on the browser through social engineering and malicious UI interactions, potentially allowing unauthorized access to browser functions or user data.

Technical details

This is an incorrect authorization vulnerability in the Browser component of Google Chrome on Android. The vulnerability requires social engineering to exploit—an attacker must trick a user into interacting with a malicious UI element to bypass system access restrictions. The attack is remote but depends on user interaction. The vulnerability was patched in Chrome version 152.0.7977.65 and later. Google assigned this a Low severity rating in the Chromium security assessment, though the external CVSS rating is 4.3 (medium).

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats