Google fixes vulnerability in Chrome for Android – over three years after it was reported

Icons on Android phone

Google has quietly fixed a security flaw in Chrome for Android that was originally reported more than three years ago.

As reported by ZDNet, the vulnerability was found by bug-hunters at Nightwatch Cybersecurity in May 2015, but wasn't addressed until Google's security staff realized that it was, in fact, a threat.

The flaw means that the mobile browser leaks information about the device it's running on, including the hardware model and firmware version – and therefore its security patch level. Chrome for desktop doesn't suffer the same issue.

Too much information

Browsers send various pieces of information to web servers as part of their normal operation, including details of the browser itself, other apps currently running, and the operating system. Unfortunately, Chrome for Android also sent the device name (such as C6606) and firmware build.

The device name might look random, but it correlates to a specific device model, and can be found easily online in readily available lists. For example, device name C6606 would be a Sony Xperia Z.

That's a security issue in itself, but the accompanying leaked firmware details are the biggest problem. 

"For many devices, this can be used to identify not only the device, but also the carrier on which it is running and from that the country," said Nightwatch Cybersecurity. "Build numbers are easily obtainable from manufacturer and phone carrier websites such as this one."

The build number can also tell attackers the device's security patch level, thereby letting them know which attacks it could be vulnerable to.

Google released a partial fix with Chrome 70 in October 2018, but the browser still releases device names and two Android components (including WebView, which is the built-in browser used by apps like Facebook) still leak the firmware build number.

Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years and is an SCA-certified barista, so whether you want to invest in some smart lights or pick up a new espresso machine, she's the right person to help.

Latest in Android
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
A phone displaying the Google Messages logo
Google Messages could finally be getting this WhatsApp-style group chat feature
Android 16 logo on a phone
Android 16 Beta 3 has arrived – here are the 4 features I think will be the most useful
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
Android 16 logo on a phone
Android 16 beta users are reporting major battery drain issues – but I’m not too worried about it
The Oppo Find N5 open to Google Maps
Android 16 brings a much-needed upgrade to Google Maps that iOS users already have
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)