DIRAS TAKE
Urgently update Chrome on Android to 152.0.7977.65 because a vendor fix is available; this prevents local apps from exploiting the incorrect authorization in CustomTabs.
What is CVE-2026-79152?
A local, co‑installed Android app can bypass web origin protections in Google Chrome, allowing unauthorized access to web content on affected Chrome builds. CVE-2026-79152 affects Chrome on Android in the 152.x branch before 152.0.7977.65; the issue is an incorrect authorization check in CustomTabs. An attacker needs a malicious app already installed on the same device — no network access or remote interaction is required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-79152 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-79152
- Update Chrome on affected Android devices to 152.0.7977.65.
- Remove or restrict untrusted co‑installed apps and audit installed app permissions.
- Monitor endpoint logs for suspicious local app behavior that attempts to interact with browser components.
- Follow any additional vendor guidance from Google for Chrome on Android.
Frequently asked questions
Is CVE-2026-79152 being actively exploited?
There are no public reports of active exploitation of CVE-2026-79152 as of 2026-09-29.
Which Chrome versions are affected by CVE-2026-79152?
Chrome on Android in the 152.x branch before 152.0.7977.65 is affected; builds fixed at 152.0.7977.65 are not vulnerable.
Is there a patch for CVE-2026-79152?
Yes, Google fixed the issue in Chrome for Android version 152.0.7977.65.
Does CVE-2026-79152 require authentication?
The vulnerability requires a local, co‑installed app on the same device; no user authentication or remote access is required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-79152
- cve.org/CVERecord?id=CVE-2026-79152
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/533083384
- All Google CVEs on CVE Radar
- CVEs published in September 2026