You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
chrome android
About this tag
The chrome android tag covers security vulnerabilities and update guidance for Google Chrome on Android devices. Recent discussions focus on multiple CVEs addressed in Chrome version 150.0.7871.47, including UI spoofing, information disclosure, and input-validation flaws. Threads emphasize the importance of updating Chrome through Google Play and verifying the installed version, as desktop Chrome is not affected by these specific issues. Topics include Autofill, Extensions, CustomTabs, WebShare, and Passwords components. The tag is useful for Android users and IT administrators seeking to understand and remediate Chrome security risks on mobile devices.
Google Chrome on Android versions earlier than 150.0.7871.47 contain CVE-2026-14126, a security-interface flaw that can allow a remote attacker to use a crafted HTML page to spoof a domain when user interaction is involved. Chromium rates the issue Low, while CISA-ADP assigns it a 4.3 Medium...
CVE-2026-14096 is a Google Chrome for Android information-disclosure flaw that can let an attacker with an already-compromised renderer leak cross-origin data through crafted HTML on versions earlier than 150.0.7871.47. Google labels the Chromium security severity Low, while CISA-ADP’s CVSS 3.1...
Google’s CVE-2026-13995 fixes a medium-severity Autofill input-validation flaw in Chrome for Android before version 150.0.7871.47. A remote attacker could use a crafted HTML page to spoof browser interface elements and mislead a user into taking an unintended action inside the browser.
The...
Google Chrome on Android versions before 150.0.7871.47 are affected by CVE-2026-13997, an incorrect-security-UI vulnerability in the browser’s Extensions component. According to the National Vulnerability Database record, a remote attacker can use crafted HTML and specific user gestures to...
Chrome for Android before 150.0.7871.47 is affected; update through Google Play
Desktop Chrome is not listed as affected in the NVD configuration.
CVE-2026-13994 is a Medium-severity Google Chrome vulnerability affecting Chrome on Android before version 150.0.7871.47. According to the National...
Google addressed CVE-2026-13955 in Chrome for Android, with version 150.0.7871.47 identified as the published fix threshold for a CustomTabs input-validation flaw that could allow a local attacker to use a malicious file for UI spoofing. The affected-product data lists Chrome on Android versions...
Chrome for Android versions earlier than 150.0.7871.47 are affected by CVE-2026-13939; update Chrome to version 150.0.7871.47 or later. Chrome on Windows is not listed as affected by the current National Vulnerability Database record.
The medium-severity WebShare input-validation flaw could...
Google Chrome on Android versions earlier than 150.0.7871.47 are vulnerable to CVE-2026-13936, a Medium-severity flaw that can let a remote attacker use crafted HTML to obtain potentially sensitive information from browser process memory after user interaction. The vulnerability is associated...
Google disclosed CVE-2026-13927 on June 30, 2026, a Chrome for Android input-validation flaw affecting versions earlier than 150.0.7871.47 that can let a local attacker escalate privileges after a user interacts with a malicious file through the browser’s interface. The vulnerability is not a...
Chrome on Android versions below 150.0.7871.47 are affected by CVE-2026-13923. Update Chrome to version 150.0.7871.47 or later and verify the installed app version.
The documented exposure is a crafted-HTML-triggered potential disclosure of sensitive information from browser process memory, not...
Google fixed CVE-2026-13924 in Chrome for Android 150.0.7871.47. The vulnerability involves insufficient validation of untrusted input in WebView and could allow a remote attacker who had already compromised the renderer process to use crafted HTML to bypass the same-origin policy. Organizations...
Google Chrome on Android before version 150.0.7871.47 is affected by CVE-2026-13887. The documented fix boundary is version 150.0.7871.47 or later. Desktop Chrome is not confirmed affected by the supplied record, even though the referenced Google release page has a desktop-oriented title...
CVE-2026-13885 affects Google Chrome on Android before version 150.0.7871.47. According to the Chrome-sourced description, crafted HTML can trigger a use-after-free condition in Skia and allow a remote attacker to execute arbitrary code inside Chrome’s sandbox. Chrome labels the vulnerability...
Google fixed CVE-2026-13870 in Chrome for Android 150.0.7871.47, closing a CWE-416 WebView use-after-free flaw triggered by crafted HTML. Before that release, a remote attacker could potentially execute arbitrary code inside the browser sandbox after required user interaction. Chromium rates the...
Google Chrome on Android versions earlier than 150.0.7871.47 are affected by CVE-2026-13868, a medium-severity flaw that the supplied National Vulnerability Database record describes as an inappropriate implementation in Chrome’s Network component. According to that record, a remote attacker who...
Google fixed CVE-2026-13872 in Chrome for Android version 150.0.7871.47. The Chrome-sourced vulnerability description says insufficient validation in WebAppInstalls could let a local attacker use a malicious file to potentially escape the browser sandbox on devices running an earlier version...
Google has fixed CVE-2026-13852, a high-severity flaw in Chrome for Android before version 150.0.7871.47 that let a local attacker use a crafted HTML page to bypass discretionary access control in WebAppInstalls, and users and administrators should treat the corrected build as the minimum safe...
CVE-2026-13822 affects Google Chrome on Android before version 150.0.7871.47. According to the published description, a remote attacker who persuades a user to install a crafted malicious extension could bypass the browser’s same-origin policy.
The documented remediation is version-based: move...
Google fixed CVE-2026-13816 in Chrome for Android 150.0.7871.47 after finding that earlier versions insufficiently validated untrusted input in the browser’s File Input component. According to the CVE description, a remote attacker could use a crafted HTML page to leak cross-origin data when a...
NVD published CVE-2026-13788 on June 30, 2026, with Chrome listed as the CVE source. The record describes a Critical use-after-free vulnerability in Google Chrome on Android versions earlier than 150.0.7871.47. A remote attacker could exploit it through a crafted HTML page to execute arbitrary...