Junglewise Threat Intelligence

CVE-2026-79286: Google Chrome missing authorization in CustomTabs on Android

CVE-2026-79286 · Severity: high · CVSS 7.4 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Chrome on Android uses CustomTabs to display web content from other apps. A missing authorization check allows a locally installed malicious app to execute arbitrary code outside Chrome's security sandbox, potentially compromising user data and device security. This requires the attacker to install their app alongside Chrome on the device.

Technical details

This is a missing authorization vulnerability in Chrome's CustomTabs component on Android. The vulnerability allows a local attacker with a co-installed app to bypass sandbox restrictions and execute arbitrary code outside Chrome's normal security boundaries. Attack vector is local (requires installation of a malicious app on the same device), and the attacker does not need to interact with the victim or have network access. The vulnerability was patched in Chrome version 152.0.7977.65 for Android. Chrome's own security classification for this issue is Medium; the external severity assessment is High.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed

References

Related threats