Executive brief
Google Chrome on Android contains a flaw in how it resolves references within CustomTabs, a component used to display web content within Android apps. A remote attacker can exploit this by crafting a malicious HTML page to bypass system access restrictions, potentially gaining unauthorized access to sensitive device or app functionality that should be protected.
Technical details
The vulnerability is an incorrect reference resolution issue in CustomTabs, a Chrome component on Android that allows apps to display web content in a customizable browser interface. An attacker can craft a malicious HTML page that exploits this flaw to bypass system access restrictions. The attack is network-based and requires only that a user visits or interacts with the attacker's crafted page. The fix is available in Chrome 152.0.7977.65 and later for Android.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed: Stable release of Chrome 152 with fix
- 2026-08-25: advisory