CVE-2026-95302 Overview
CVE-2026-95302 is an incorrect authorization vulnerability [CWE-863] in the WebAPKs component of Google Chrome on Android. Versions of Chrome prior to 154.0.8037.57 fail to properly enforce cross-origin boundaries when a co-installed application is present on the device. A local attacker with a malicious companion app installed on the same Android device can obtain cross-origin data that should remain isolated. Google Chromium rated this issue Medium severity, while the NVD assigns a low base score reflecting the local attack vector, high attack complexity, and limited confidentiality impact only.
Critical Impact
A locally installed malicious Android application can leverage WebAPK authorization gaps in Chrome to read cross-origin data from other web origins.
Affected Products
- Google Chrome for Android prior to 154.0.8037.57
- Google Android devices running vulnerable Chrome builds
- WebAPK-based Progressive Web Applications delivered through Chrome
Discovery Timeline
- 2026-09-29 - CVE-2026-95302 published to the National Vulnerability Database
- 2026-09-30 - Last updated in NVD database
- 2026-09 - Google published the Chrome Stable Channel update addressing the issue
Technical Details for CVE-2026-95302
Vulnerability Analysis
The vulnerability resides in Chrome's WebAPK subsystem on Android. WebAPKs are lightweight Android packages that Chrome generates and installs to launch Progressive Web Apps (PWAs) as first-class Android applications. Chrome enforces origin isolation for the web content rendered inside these WebAPKs so that one origin cannot read data belonging to another.
Because the affected code path performs an incorrect authorization check, Chrome does not adequately validate the identity or origin scope of a caller when a co-installed Android application interacts with the WebAPK. The result is a scoped cross-origin data disclosure that bypasses the Same-Origin Policy boundary Chrome is expected to uphold.
Exploitation requires local access, the presence of an attacker-controlled companion Android app on the same device, and specific runtime conditions. This raises attack complexity but does not require user interaction or elevated privileges once the malicious app is installed.
Root Cause
The root cause is a missing or insufficient authorization decision in the WebAPK code path that mediates requests from other installed Android applications. The check does not verify that the requesting app is authorized to access data associated with the WebAPK's origin, allowing cross-origin reads. This aligns with the classification of Incorrect Authorization under CWE-863.
Attack Vector
An attacker must first convince the user to install a malicious Android application, for example through a sideloaded APK or a Play Store app that later behaves maliciously. Once installed, the co-resident app interacts with Chrome's WebAPK interfaces to trigger the flawed authorization path and read data belonging to a different web origin rendered through a WebAPK. There is no remote, network-only exploitation path.
No public proof-of-concept, exploit code, or in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Technical details are tracked in Chromium Issue #502242455.
Detection Methods for CVE-2026-95302
Indicators of Compromise
- Newly sideloaded or recently installed Android applications that request unusual interaction with Chrome or installed WebAPKs.
- Android apps issuing intents or bindings targeting Chrome WebAPK package names outside expected PWA launch flows.
- Unexpected data appearing in third-party applications that mirrors content from a user's authenticated PWA sessions.
Detection Strategies
- Inventory mobile fleets for Chrome for Android versions below 154.0.8037.57 using mobile device management (MDM) reporting.
- Review installed application lists on managed Android devices for unknown or unvetted packages co-existing with business-critical PWAs.
- Correlate Android application install events with subsequent anomalous access to internal web applications delivered as WebAPKs.
Monitoring Recommendations
- Enable MDM policies that report Chrome version and installed application inventory to a central log store for continuous evaluation.
- Alert on installation of apps from unknown sources on devices that access sensitive internal PWAs.
- Track Chrome update compliance over time and prioritize devices that remain on pre-154.0.8037.57 builds.
How to Mitigate CVE-2026-95302
Immediate Actions Required
- Update Google Chrome on Android to version 154.0.8037.57 or later through the Google Play Store.
- Audit managed Android devices and force pending Chrome updates via MDM where possible.
- Restrict installation of applications from unknown sources on devices that access sensitive PWAs or corporate web resources.
Patch Information
Google released a fix in the Chrome Stable Channel update. Users and administrators should ensure Chrome for Android is on 154.0.8037.57 or later. Refer to the Chrome Releases Stable Channel Update for the vendor advisory.
Workarounds
- Uninstall untrusted or unnecessary Android applications, particularly those recently sideloaded, until Chrome is patched.
- Access sensitive web applications through a fully patched browser session rather than a WebAPK on unpatched devices.
- Enforce Google Play Protect and disable installation from unknown sources through Android enterprise policy.
# Example MDM query: identify Android devices running vulnerable Chrome builds
# Pseudocode - adapt to your MDM's query language
SELECT device_id, user, os_version, app_version
FROM installed_apps
WHERE package_name = 'com.android.chrome'
AND app_version < '154.0.8037.57';
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
