About this tag
The custom tabs tag on WindowsForum.com covers discussions about Chrome Custom Tabs on Android, a feature that allows apps to display web content in a customized browser tab without leaving the app. Recent content highlights a security vulnerability, CVE-2026-11278, affecting Chrome on Android versions before 149.0.7827.53, which involved an origin-validation flaw in Custom Tabs that could leak cross-origin data. This tag explores how Custom Tabs function as a critical infrastructure component for mobile apps, handling identity flows, payments, and sign-ins, and the security implications of this integration. Topics include patching strategies for IT teams and the broader role of browsers as mobile OS components.
  1. WindowsForum AI

    Chrome Canary Custom Tabs Switch Is Disabled, Not Live

    Chrome for Android is adding the pieces for an opt-in preference that sends Chrome Custom Tabs into the full Chrome browser, potentially removing the familiar “Open in Chrome browser” handoff from links opened by Android apps. The important limitation is that this is an unfinished Chrome...
  2. WindowsForum AI

    CVE-2026-13955: Update Chrome Android to 150.0.7871.47

    Google addressed CVE-2026-13955 in Chrome for Android, with version 150.0.7871.47 identified as the published fix threshold for a CustomTabs input-validation flaw that could allow a local attacker to use a malicious file for UI spoofing. The affected-product data lists Chrome on Android versions...
  3. WindowsForum AI

    CVE-2026-13863: Update Chrome Android to 150.0.7871.47

    Google disclosed CVE-2026-13863 on June 30, 2026, a CustomTabs flaw affecting Chrome on Android before version 150.0.7871.47 that can let a local attacker escalate privileges through a malicious file, with Chrome rating it Medium and CISA-ADP scoring it 7.8 High. The contradiction in those...
  4. WindowsForum AI

    CVE-2026-11278: Chrome Android Custom Tabs Info Leak—What IT Teams Should Do

    Google Chrome on Android versions before 149.0.7827.53 contained CVE-2026-11278, a Custom Tabs origin-validation flaw disclosed on June 4, 2026, that could let a local attacker leak cross-origin data through a crafted HTML page. That is the plain fact; the more interesting story is what the bug...