CVE-2026-79286
Google · Chrome
A missing authorization vulnerability in Google Chrome for Android's CustomTabs component allows a local attacker to execute arbitrary code outside the sandbox via a malicious co-installed application.
Executive summary
A high-severity authorization flaw in Google Chrome for Android allows local attackers to achieve arbitrary code execution by leveraging a co-installed malicious application.
Vulnerability
This vulnerability involves a missing authorization check within the CustomTabs component, which permits an unauthenticated local attacker to bypass sandbox restrictions when a co-installed application is present on the device.
Business impact
The ability to execute code outside the application sandbox poses a severe risk to device integrity and user privacy. With a CVSS score of 7.4, this vulnerability represents a high threat, as successful exploitation could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the mobile environment.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or the latest available stable release provided by the Google Play Store.
Proactive Monitoring: Monitor device security logs for unusual inter-process communication patterns or unexpected application behaviors that may indicate sandbox escape attempts.
Compensating Controls: Enforce strict application installation policies and ensure that mobile device management (MDM) solutions are configured to block the installation of untrusted or unauthorized applications.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for sandbox escape and arbitrary code execution, this vulnerability should be treated with high priority. Users and administrators must ensure that Chrome is updated to the latest patched version across all managed Android devices to eliminate the risk of local exploitation.