• PATCH AVAILABLE

CVE-2026-79152: authorization bypass in Google Chrome

A local, co‑installed Android app can bypass web origin protections in Google Chrome, allowing unauthorized access to web content on affected Chrome builds. CVE-2026-79152 affects Chrome on Android in the 152.x branch before 152.0.7977.65; the issue is an incorrect authorization check in CustomTabs. An attacker needs a malicious app already installed on the same device — no network access or remote interaction is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00321
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently update Chrome on Android to 152.0.7977.65 because a vendor fix is available; this prevents local apps from exploiting the incorrect authorization in CustomTabs.

What is CVE-2026-79152?

A local, co‑installed Android app can bypass web origin protections in Google Chrome, allowing unauthorized access to web content on affected Chrome builds. CVE-2026-79152 affects Chrome on Android in the 152.x branch before 152.0.7977.65; the issue is an incorrect authorization check in CustomTabs. An attacker needs a malicious app already installed on the same device — no network access or remote interaction is required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.65 – before 152.0.7977.65152.0.7977.65

Is CVE-2026-79152 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-79152

  1. Update Chrome on affected Android devices to 152.0.7977.65.
  2. Remove or restrict untrusted co‑installed apps and audit installed app permissions.
  3. Monitor endpoint logs for suspicious local app behavior that attempts to interact with browser components.
  4. Follow any additional vendor guidance from Google for Chrome on Android.

Frequently asked questions

Is CVE-2026-79152 being actively exploited?

There are no public reports of active exploitation of CVE-2026-79152 as of 2026-09-29.

Which Chrome versions are affected by CVE-2026-79152?

Chrome on Android in the 152.x branch before 152.0.7977.65 is affected; builds fixed at 152.0.7977.65 are not vulnerable.

Is there a patch for CVE-2026-79152?

Yes, Google fixed the issue in Chrome for Android version 152.0.7977.65.

Does CVE-2026-79152 require authentication?

The vulnerability requires a local, co‑installed app on the same device; no user authentication or remote access is required.

References