PT-2026-99613 · Google · Chrome On Android

CVE-2026-95302

·

Published

2026-09-26

·

Updated

2026-09-29

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome on Android versions prior to 154.0.8037.57
Description Incorrect authorization in WebAPKs allows a local attacker to obtain cross-origin data through a co-installed application. Cross-origin data refers to information belonging to a different origin (domain, protocol, or port) than the one requesting it.
Recommendations Update Google Chrome on Android to version 154.0.8037.57 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95302
OPENSUSE-SU-2026:11888-1

Affected Products

Chrome On Android