Executive brief
Google Chrome on Android contains a flaw in TrustedWebActivities (a feature that integrates web content with native Android apps) that fails to properly verify user authorization. A local attacker who can install a malicious app on the same device could exploit this to access sensitive information that the user has shared with trusted web apps, potentially compromising personal data or credentials.
Technical details
The vulnerability is a missing authorization check in the TrustedWebActivities component of Google Chrome on Android. The flaw allows a co-installed local application to bypass authorization controls and obtain sensitive information accessible through trusted web activities. The attack requires local access (a second app installed on the device) and does not require network interaction or user authentication. An attacker can leverage this to read sensitive data that would normally be restricted to authorized web contexts. The issue is fixed in Chrome version 153.0.8010.36 and later for Android.
Affected products
- Google Chrome Android prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released