Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-78949

CVE-2026-78949: Chrome Android CustomTabs Data Leak

CVE-2026-78949 is an information disclosure vulnerability in Chrome for Android CustomTabs that allows local attackers to obtain cross-origin data through co-installed apps. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-78949 Overview

CVE-2026-78949 is an observable discrepancy vulnerability in the CustomTabs component of Google Chrome on Android versions prior to 152.0.7977.65. A co-installed malicious application can leverage the discrepancy to infer cross-origin data that should remain isolated from other apps on the device. Google's Chromium team classified the security severity as Medium. The weakness is tracked under CWE-203: Observable Discrepancy, which covers information leaks through observable behavioral or timing differences. Exploitation requires local access via a co-installed Android app rather than a remote network position.

Critical Impact

A local, co-installed Android application can obtain cross-origin data handled by Chrome CustomTabs, breaking the same-origin isolation model expected by web applications.

Affected Products

  • Google Chrome for Android prior to 152.0.7977.65
  • Chromium-based browsers on Android that embed the vulnerable CustomTabs implementation
  • Android applications that rely on Chrome CustomTabs for authentication or web content rendering

Discovery Timeline

  • 2026-08-25 - CVE-2026-78949 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-78949

Vulnerability Analysis

The flaw resides in Chrome's CustomTabs feature on Android. CustomTabs allow native Android apps to display web content using Chrome as the rendering engine while retaining browser cookies, autofill, and session context. An observable discrepancy in the component's behavior lets a co-installed application distinguish between different cross-origin states.

Because CustomTabs share state with the primary Chrome browser profile, any leakage of behavioral signals can be correlated back to authenticated web sessions. The result is a cross-origin data disclosure that undermines the origin isolation boundary between web content and third-party Android apps.

Root Cause

The root cause maps to [CWE-203], where two code paths produce distinguishable behaviors based on data that should remain confidential. In this case, the discrepancy is observable from another local application, allowing that application to infer state tied to a different web origin without direct access to the underlying data.

Attack Vector

Exploitation requires an attacker to place a malicious application on the same Android device as the vulnerable Chrome build. The attacker's app interacts with CustomTabs and measures the observable differences produced by the target user's cross-origin state. No user credentials or elevated Android permissions are described as prerequisites in the advisory. Technical specifics are tracked in Chromium Issue #517910756.

No verified public proof-of-concept code is available. Refer to the Google Chrome Stable Update announcement for vendor-provided context.

Detection Methods for CVE-2026-78949

Indicators of Compromise

  • Presence of Chrome for Android builds earlier than 152.0.7977.65 on managed devices.
  • Unexpected Android applications that repeatedly invoke CustomTabsIntent or bind to Chrome's CustomTabs service.
  • Anomalous inter-process communication patterns between third-party apps and the com.android.chrome package.

Detection Strategies

  • Inventory Chrome versions across the Android mobile fleet using MDM or UEM telemetry and flag hosts below 152.0.7977.65.
  • Review installed application lists for low-reputation apps that request browser integration or web-view launching capabilities.
  • Correlate authentication anomalies on web properties with Android devices running affected Chrome builds.

Monitoring Recommendations

  • Enable MDM policies that report Chrome version drift and mandate automatic updates from the Google Play Store.
  • Alert on installation of sideloaded APKs on managed Android endpoints, since local exploitation requires a co-installed app.
  • Monitor identity provider logs for session anomalies originating from Android User-Agent strings tied to unpatched Chrome versions.

How to Mitigate CVE-2026-78949

Immediate Actions Required

  • Update Google Chrome for Android to version 152.0.7977.65 or later through the Google Play Store.
  • Enforce Chrome auto-update policies via Android Enterprise or MDM configuration.
  • Restrict installation of untrusted or sideloaded Android applications on corporate-managed devices.
  • Educate users about the risk of installing apps from outside the Google Play Store, since exploitation requires a co-installed app.

Patch Information

Google addressed CVE-2026-78949 in Chrome 152.0.7977.65 for Android. Details are published in the Google Chrome Stable Update announcement, with implementation notes referenced in Chromium Issue #517910756. Chromium downstream vendors should incorporate the corresponding upstream fix.

Workarounds

  • Use Android work profiles to isolate corporate browsing from personal apps on the same device.
  • Disable or avoid Chrome CustomTabs integrations in high-risk apps until the patched Chrome build is deployed.
  • Block installation of non-Play Store applications through MDM policy to reduce the co-installed app attack surface.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.