External risk intelligence

Google Chrome for Android CustomTabs Authorization Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-79152

The vulnerability requires a local attacker to have a co-installed malicious application on the device to exploit the authorization flaw in the Chrome CustomTabs component. This is a local-only, device-resident attack vector and is not reachable from the public internet.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves an authorization flaw within Google Chrome's CustomTabs feature on Android. While rated as critical, the main concern at this time is confirming if your organization utilizes affected technology, as the exploitation requires a local attacker with a co-installed malicious app.

  • Flaw in Chrome's Android feature bypasses security rules.
  • Confirm relevance: exploitation requires local, co-installed app.
  • Understand exposure, not immediate direct threat.

Attack Path

How an attacker could exploit the issue

An attacker could leverage a co-installed malicious application on an Android device to circumvent web origin restrictions within Chrome's CustomTabs feature. This bypass could potentially allow the malicious app to interact with web content in ways not intended by the user or the website. The specific vulnerability lies in how Chrome handles authorization for these custom tabs.

  • Local attacker with co-installed app.
  • Bypasses web origin policy in CustomTabs.
  • Unauthorized access to web content.

Live Threat

Current exploitation, exposure, and threat context

A local attacker with a co-installed app could bypass Chrome's web origin policy on Android, potentially affecting how web content is displayed and interacted with.

  • Bypassed web origin policy.
  • Co-installed app exploits authorization.
  • May affect web content interaction.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability, affecting the CustomTabs component in Google Chrome on Android, is classified as having a low severity but could allow a local attacker to bypass web origin policies. Real-world ownership likely falls to the platform or mobile application teams responsible for managing the Android environment and its core components. The initial practical move involves identifying all Android devices where Chrome is used, determining if any co-installed applications could pose a risk, and then prioritizing remediation based on the potential impact and user base.

  • Platform or mobile app teams own the issue.
  • Verify local co-installed app reachability.
  • Plan remediation for critical devices.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome CustomTabs on Android?

CustomTabs is a feature that allows apps to open web pages directly within a Chrome-powered browser window inside the app itself. Instead of launching a separate browser app, this provides a seamless browsing experience while keeping the user within the original application's context.

What does CWE-863 mean for CVE-2026-79152?

CWE-863 stands for Incorrect Authorization. In the context of this CVE, it means the software does not properly verify if an application has permission to perform specific actions. Because of this flaw, Chrome fails to enforce web origin policies, allowing an unauthorized app to interact with sensitive data it should not be able to access.

How is this Chrome vulnerability triggered?

An attacker triggers this bug by having a malicious application already installed on the same Android device as the user's Chrome browser. It cannot be triggered by simply visiting a malicious website or opening a link; the attack requires a secondary, co-installed app to interact with the CustomTabs component locally.

Do I need to worry about remote attacks for this CVE?

According to Halo Surface Signal, this is considered a local-only, device-resident attack vector. Because the flaw requires an app to be physically co-installed on the Android device to exploit the authorization gap, it is not reachable from the public internet.

What steps should I take if I use Chrome on Android?

The most effective first step is to ensure Google Chrome is updated to version 152.0.7977.65 or higher, which resolves the underlying authorization logic. Additionally, maintain good mobile security hygiene by only installing applications from trusted sources to prevent the presence of unauthorized or malicious software on your devices.

References