PT-2026-81561 · Google · Chrome On Android

CVE-2026-78949

·

Published

2026-08-25

·

Updated

2026-09-01

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome on Android versions prior to 152.0.7977.65
Description An observable discrepancy in CustomTabs allows a local attacker to obtain cross-origin data through a co-installed application. Cross-origin data refers to information belonging to a different origin (domain, protocol, or port) than the one requesting it.
Recommendations Update Google Chrome on Android to version 152.0.7977.65 or later.

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78949
ECHO-5E3B-54A8-7FE0
OPENSUSE-SU-2026:11628-1
OPENSUSE-SU-2026:21724-1

Affected Products

Chrome On Android