Executive brief
Google Chrome for Android contains a missing authorization vulnerability that allows a locally-installed malicious app to access sensitive information from Chrome without proper permission checks. An attacker with a co-installed application can exploit this to exfiltrate user data such as credentials, browsing history, or other confidential information stored within Chrome.
Technical details
This vulnerability is a missing authorization/access control flaw in Google Chrome's Android implementation where sensitive data or functionality is accessible to co-installed applications without proper permission validation. The attack vector is local; an attacker must have a malicious application already installed on the same Android device. The vulnerable versions are Chrome on Android prior to 153.0.8010.47. A co-installed app can exploit the missing authorization check to access sensitive information. Google has patched this issue in Chrome 153.0.8010.47 and later releases.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Chrome 153.0.8010.47