Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79222

CVE-2026-79222: Google Chrome CustomTabs Auth Bypass Flaw

CVE-2026-79222 is an authorization bypass in Google Chrome CustomTabs on Android that lets local attackers bypass web origin policy through co-installed apps. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-79222 Overview

CVE-2026-79222 is an incorrect authorization vulnerability [CWE-863] in the CustomTabs component of Google Chrome on Android. The flaw affects versions prior to 152.0.7977.65 and allows a local attacker to bypass the web origin policy through a co-installed malicious application. Google has rated the Chromium security severity as Medium.

The vulnerability requires local access via a co-installed Android app, limiting mass exploitation. However, it undermines a core browser security boundary by permitting cross-origin policy bypass through inter-app interactions on Android devices.

Critical Impact

A co-installed Android application can bypass Chrome's web origin policy through CustomTabs, potentially enabling unauthorized access to web content or session context tied to other origins.

Affected Products

  • Google Chrome on Android prior to 152.0.7977.65
  • Chrome CustomTabs component on Android
  • Android devices running vulnerable Chrome builds alongside untrusted applications

Discovery Timeline

  • 2026-08-25 - CVE-2026-79222 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79222

Vulnerability Analysis

The vulnerability resides in Chrome's CustomTabs implementation on Android. CustomTabs allow third-party apps to launch a Chrome-rendered browser tab from within their own user interface. This integration relies on strict authorization checks to ensure that a hosting app cannot influence or observe content bound to another web origin.

In affected Chrome versions, an incorrect authorization check permits a co-installed app to interact with CustomTabs in a way that violates the web origin policy. This weakens the isolation boundary between the invoking Android app and web content Chrome renders. The Common Weakness Enumeration classifies this pattern as [CWE-863] Incorrect Authorization.

Root Cause

The root cause is an authorization decision within the CustomTabs code path that does not correctly enforce origin-based access control. The check fails to distinguish between legitimate and unauthorized callers when a co-installed app initiates or interacts with a CustomTabs session. This gap allows a local Android application to obtain access or influence it should not have under the same-origin model.

Attack Vector

Exploitation requires the attacker to have an application installed on the same Android device as vulnerable Chrome. The malicious app invokes CustomTabs in a manner that triggers the authorization flaw, then leverages the bypass to interact with content bound to a different web origin. No remote network position is required, and user interaction is limited to installing the co-resident application.

No verified public proof-of-concept is available. Consult the Chromium Issue Tracker #496195129 and the Google Chrome Stable Update advisory for vendor-provided technical details.

Detection Methods for CVE-2026-79222

Indicators of Compromise

  • Unexpected Android applications invoking Chrome CustomTabs with URLs targeting sensitive origins such as banking, corporate SSO, or webmail.
  • Chrome CustomTabs sessions initiated shortly after installation of unknown or sideloaded APKs.
  • Anomalous android.support.customtabs intent activity originating from apps outside an approved allowlist.

Detection Strategies

  • Inventory managed Android devices to identify Chrome versions below 152.0.7977.65 using mobile device management (MDM) reporting.
  • Monitor Android package installation events for unsigned or sideloaded applications on devices used for sensitive web access.
  • Correlate CustomTabs intent activity with subsequent authentication anomalies in web application logs tied to the affected user identities.

Monitoring Recommendations

  • Ingest MDM and endpoint telemetry into a centralized data lake to track Chrome version drift across the Android fleet.
  • Alert on Chrome for Android installations that remain below the patched build after a defined remediation window.
  • Review web application authentication logs for unexpected session activity originating from mobile Chrome clients.

How to Mitigate CVE-2026-79222

Immediate Actions Required

  • Update Google Chrome on Android to version 152.0.7977.65 or later through the Google Play Store.
  • Enforce automatic Chrome updates on managed Android devices via MDM configuration.
  • Restrict installation of untrusted or sideloaded applications on devices used for sensitive browsing.
  • Audit installed Android applications and remove any that are unknown, unused, or lacking a legitimate business purpose.

Patch Information

Google addressed CVE-2026-79222 in Chrome 152.0.7977.65 for Android. Refer to the Google Chrome Stable Update advisory for release details and the Chromium Issue Tracker #496195129 for the underlying fix reference.

Workarounds

  • Limit Android device usage for sensitive web sessions to devices with the patched Chrome version deployed.
  • Use Android Work Profile or enterprise containerization to isolate corporate browsing from personal or untrusted applications.
  • Deploy application allowlisting through MDM to block installation of unapproved co-resident apps that could abuse CustomTabs.
bash
# Verify installed Chrome version on a managed Android device via adb
adb shell dumpsys package com.android.chrome | grep versionName

# Expected output should show versionName=152.0.7977.65 or later

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.