Skip to main content
Vulnerability Database/CVE-2026-95328

CVE-2026-95328: Google Chrome Information Disclosure Flaw

CVE-2026-95328 is an information disclosure vulnerability in Google Chrome on Android that allows local attackers to obtain sensitive data through social engineering. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-95328 Overview

CVE-2026-95328 is a confused deputy vulnerability [CWE-441] in the Mobile component of Google Chrome on Android before version 154.0.8037.57. A local attacker who convinces a user to install a malicious co-installed application can leverage Chrome's privileges to obtain sensitive information. Exploitation requires user interaction through social engineering, but no elevated privileges are needed on the device. Google classified the underlying Chromium security severity as Low, while the NVD assigned a medium CVSS rating based on the confidentiality impact.

Critical Impact

A co-installed Android application can trick Chrome into disclosing sensitive user data by abusing Chrome's inherited permissions and inter-process communication surface.

Affected Products

  • Google Chrome for Android prior to 154.0.8037.57
  • Google Android (host platform)
  • Chromium-based mobile builds sharing the affected Mobile component

Discovery Timeline

  • 2026-09-29 - CVE CVE-2026-95328 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-95328

Vulnerability Analysis

The flaw is a confused deputy condition in Chrome's Mobile subsystem on Android. Chrome exposes interfaces that other locally installed apps can invoke through Android inter-process communication mechanisms such as Intents, content providers, or exported activities. When Chrome acts on these requests, it does so with its own permissions and access to user data, including browsing context and stored resources. A co-installed malicious app can craft requests that cause Chrome to perform actions on the attacker's behalf, returning sensitive information the calling app would not otherwise be entitled to read.

Because the attack requires the victim to install and interact with the malicious app, exploitation depends on social engineering. Once the app is present, no additional privileges are required to trigger the disclosure.

Root Cause

The root cause is insufficient validation of the requesting caller or the requested resource within an exposed Chrome-on-Android interface. Chrome's Mobile component treats an inbound request as legitimate and executes it using Chrome's own authority, satisfying the classic confused deputy pattern described by CWE-441.

Attack Vector

The attacker publishes or side-loads an Android application onto the victim's device. That app issues crafted requests to Chrome's exposed component and receives sensitive data in the response. Details of the specific interface and payload are tracked in Chromium Issue Tracker #553148673 and summarized in the Google Chrome Releases advisory.

No public proof-of-concept code is available at time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-95328

Indicators of Compromise

  • Installation of unknown or side-loaded Android applications shortly before anomalous Chrome activity.
  • Android Intents or content provider queries directed at Chrome package identifiers from non-browser apps.
  • Chrome for Android running a version earlier than 154.0.8037.57 on managed devices.

Detection Strategies

  • Inventory mobile endpoints and flag Chrome for Android builds below 154.0.8037.57 through mobile device management (MDM) reporting.
  • Review Android package manager logs for apps that declare queries or bindings targeting Chrome components.
  • Correlate mobile threat defense alerts on suspicious app installs with Chrome IPC activity to surface confused deputy exploitation attempts.

Monitoring Recommendations

  • Enable Google Play Protect and any enterprise mobile threat defense agent to catch malicious co-installed applications.
  • Monitor MDM compliance dashboards for out-of-date Chrome versions and non-compliant install sources such as unknown APK origins.
  • Track user-reported phishing or social engineering attempts that direct users to install helper or companion apps alongside Chrome.

How to Mitigate CVE-2026-95328

Immediate Actions Required

  • Update Google Chrome on Android to version 154.0.8037.57 or later through the Google Play Store.
  • Audit installed applications on managed Android devices and remove any unknown or unsanctioned packages.
  • Restrict installation of apps from unknown sources through MDM policy on enterprise devices.

Patch Information

Google addressed the issue in Chrome for Android 154.0.8037.57. Refer to the Google Chrome Releases advisory for the stable channel update and to Chromium Issue Tracker #553148673 for the underlying bug reference.

Workarounds

  • Disable installation of apps from unknown sources and enforce Google Play as the sole install channel.
  • Educate users to reject prompts that instruct them to install companion applications alongside their browser.
  • Uninstall recently added apps of unclear provenance until Chrome has been updated.
bash
# Verify Chrome for Android version via ADB on a managed test device
adb shell dumpsys package com.android.chrome | grep versionName

# Enforce Play-only installs through MDM (example: block unknown sources)
# Policy key: install_unknown_sources_disabled = true

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.