ZeroHour

CVE-2026-87481

mass

Incorrect Authorization in Chrome WebView on Android Enables Sandbox Escape

CVSS 3.1
8.3 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-87481 is an incorrect authorization flaw (CWE-863) in the WebView component of Google Chrome on Android, fixed in version 153.0.8010.36. To trigger it, an attacker crafts a malicious HTML page that a user must load; after compromising the browser's renderer process, the flaw lets the attacker bypass an authorization check and execute arbitrary code outside the browser sandbox. Successful exploitation effectively turns a renderer-level compromise into a sandbox escape, with high confidentiality, integrity, and availability impact on the affected Android device. Only Chrome on Android prior to 153.0.8010.36 is named as affected; desktop platforms and other products are not listed in the advisory. No public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.3%, 23rd percentile) indicate no confirmed exploitation at this time, though Google's CVSS score of 8.3 (High) reflects the severity of the potential impact.

What to do: Update Google Chrome on Android to version 153.0.8010.36 or later via Google Play, and verify the installed version on managed devices through MDM or the browser's About/Settings page. As an interim mitigation, avoid loading untrusted web content in Chrome on Android, since exploitation requires both a crafted HTML page and a prior renderer-process compromise. Note the flaw is rated Medium by Chromium but High (8.3) under CVSS, so prioritize patching internet-facing and at-risk mobile fleets despite the absence of known exploitation.

Affected
Google Chrome (on Android)all versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome and WebView ship on effectively all modern Android devices) — Chrome for Android and the WebView component are distributed on the overwhelming majority of the world's several billion active Android devices, so the exposed population is at the multi-billion user scale, though exploitation additionally…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.