CVE-2026-87481
massIncorrect Authorization in Chrome WebView on Android Enables Sandbox Escape
CVE-2026-87481 is an incorrect authorization flaw (CWE-863) in the WebView component of Google Chrome on Android, fixed in version 153.0.8010.36. To trigger it, an attacker crafts a malicious HTML page that a user must load; after compromising the browser's renderer process, the flaw lets the attacker bypass an authorization check and execute arbitrary code outside the browser sandbox. Successful exploitation effectively turns a renderer-level compromise into a sandbox escape, with high confidentiality, integrity, and availability impact on the affected Android device. Only Chrome on Android prior to 153.0.8010.36 is named as affected; desktop platforms and other products are not listed in the advisory. No public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.3%, 23rd percentile) indicate no confirmed exploitation at this time, though Google's CVSS score of 8.3 (High) reflects the severity of the potential impact.
What to do: Update Google Chrome on Android to version 153.0.8010.36 or later via Google Play, and verify the installed version on managed devices through MDM or the browser's About/Settings page. As an interim mitigation, avoid loading untrusted web content in Chrome on Android, since exploitation requires both a crafted HTML page and a prior renderer-process compromise. Note the flaw is rated Medium by Chromium but High (8.3) under CVSS, so prioritize patching internet-facing and at-risk mobile fleets despite the absence of known exploitation.
| Google Chrome (on Android) | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.