Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-18000

CVE-2026-18000: Google Chrome USB Information Disclosure

CVE-2026-18000 is an information disclosure vulnerability in Google Chrome on Android that allows attackers to leak cross-origin data. This article covers the technical details, affected versions, and mitigation strategies.

Updated:

CVE-2026-18000 Overview

CVE-2026-18000 is an insufficient policy enforcement vulnerability in the USB component of Google Chrome on Android. The flaw affects versions prior to 151.0.7922.72. A remote attacker who has already compromised the renderer process can leak cross-origin data through a crafted HTML page. Google classifies the Chromium security severity as Low.

The issue centers on missing or incomplete origin checks within the USB subsystem exposed to web content. Exploitation requires a prior foothold in the renderer, which limits the population of attackers capable of leveraging it.

Critical Impact

An attacker with an existing compromised renderer process can bypass same-origin protections in the USB implementation and exfiltrate cross-origin data from a targeted Android Chrome user.

Affected Products

  • Google Chrome on Android prior to 151.0.7922.72
  • Chromium-based browsers on Android that incorporate the vulnerable USB component
  • Downstream Android WebView builds derived from vulnerable Chromium versions

Discovery Timeline

  • 2026-07-30 - CVE-2026-18000 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-18000

Vulnerability Analysis

The vulnerability resides in Chrome's USB implementation on Android, where policy enforcement between origins is incomplete. The USB API surface is intended to gate device access and cross-origin data flows behind explicit user consent and origin checks. In vulnerable builds, at least one code path in this subsystem fails to enforce those constraints when invoked from a compromised renderer.

Because the flaw sits behind a compromised renderer requirement, it functions as a secondary primitive in a multi-stage attack. Chained with a renderer exploit, it expands the attacker's reach from a single origin into cross-origin data belonging to other sites the user has visited or is currently browsing. The public advisory does not disclose the specific USB code path or object involved.

Root Cause

The root cause is insufficient policy enforcement in the USB feature on Android. Origin or permission checks that should isolate USB-mediated data between web origins are either missing or bypassable when driven from a renderer under attacker control. The Chromium tracker entry issues.chromium.org/issues/521623907 holds the internal analysis, which is restricted at time of publication.

Attack Vector

An attacker must first compromise the Chrome renderer process on the victim's Android device, typically through a separate memory corruption or logic bug reached from a malicious or hijacked web page. Once the renderer is under attacker control, the attacker delivers a crafted HTML payload that drives the USB code paths to read data associated with other origins. The exfiltrated data is then sent back to attacker-controlled infrastructure.

No verified proof-of-concept code is available. See the Chromium Issue #521623907 and the Google Chrome Stable Update for additional context.

Detection Methods for CVE-2026-18000

Indicators of Compromise

  • Android Chrome instances reporting a version string below 151.0.7922.72 in telemetry or user-agent logs.
  • Unexpected outbound HTTPS traffic from Chrome on Android to previously unseen domains shortly after visiting a suspicious page.
  • Web sessions where a single tab appears to access data associated with unrelated origins in a short time window.

Detection Strategies

  • Inventory Android endpoints and flag any device where the installed Chrome version is below 151.0.7922.72.
  • Correlate browser process anomalies on Android with subsequent network egress to non-corporate destinations to spot post-exploitation exfiltration.
  • Review mobile threat defense alerts for renderer crashes or sandbox anomalies in Chrome that could indicate the prerequisite renderer compromise.

Monitoring Recommendations

  • Ingest Chrome version telemetry from mobile device management into the SIEM to track patch coverage over time.
  • Monitor for delivery of suspicious HTML content, including pages that aggressively request USB permissions or reference the WebUSB API.
  • Track outbound data volumes from Android browser sessions to identify potential cross-origin data leaks.

How to Mitigate CVE-2026-18000

Immediate Actions Required

  • Update Google Chrome on Android to version 151.0.7922.72 or later through the Google Play Store.
  • Push the update through enterprise mobility management to all managed Android devices and confirm compliance.
  • Restrict or block WebUSB usage on managed browsers where the feature is not required for business workflows.

Patch Information

Google addressed the issue in the Chrome Stable channel release documented in the Google Chrome Stable Update. Users must install Chrome 151.0.7922.72 or later on Android. Downstream Chromium-based Android browsers should pick up the corresponding upstream fix.

Workarounds

  • Disable or restrict the WebUSB API via enterprise policy on managed Chrome installations until patching is complete.
  • Advise users to avoid granting USB device permissions to untrusted sites and to close unused browser tabs.
  • Enforce mobile application allowlisting so only patched Chrome builds can run on corporate Android devices.
bash
# Configuration example
# Chrome enterprise policy to disable WebUSB across managed Android devices
# Deploy via Google Admin console or supported MDM as a Chrome policy payload
{
  "DefaultWebUsbGuardSetting": 2,
  "WebUsbBlockedForUrls": ["*"]
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.