CVE-2026-79152

Google · Chrome

An incorrect authorization vulnerability in Google Chrome for Android's CustomTabs allows a local attacker to bypass web origin policy through a co-installed malicious application.

Executive summary

Google Chrome for Android contains a critical authorization flaw that enables local attackers to bypass web origin policies and potentially achieve full system compromise.

Vulnerability

This vulnerability is caused by incorrect authorization in the CustomTabs component, which permits an unauthenticated local attacker to bypass web origin restrictions via a co-installed application.

Business impact

While the vendor classifies the severity as Low, the CVSS score of 9.8 indicates a critical risk to data confidentiality, integrity, and availability. A successful exploit allows an attacker to bypass critical security boundaries, potentially leading to unauthorized access to sensitive user data, credential theft, or the execution of arbitrary actions within the context of the browser.

Remediation

Immediate Action: Update Google Chrome on all Android devices to version 152.0.7977.65 or later via the Google Play Store immediately.

Proactive Monitoring: Review mobile device management (MDM) logs for unauthorized or suspicious applications installed on corporate-managed devices.

Compensating Controls: Enforce strict application allow-listing policies via MDM to prevent the installation of untrusted or potentially malicious co-installed applications on corporate devices.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS score, organizations must treat this vulnerability with high priority despite the vendor's internal severity classification. Administrators should prioritize the deployment of the latest Chrome update across their mobile fleet to ensure the authorization flaw is remediated and the web origin policy is correctly enforced.

More Google CVEs

Sources