ZeroHour

CVE-2026-87483

PoC mass

Incorrect Authorization in Chrome for Android Bypasses System Access Restrictions

CVSS 3.1
6.5 medium
EPSS
<1%p16
Published
()
Modified
AI analysis

An incorrect authorization flaw (CWE-863) in the Browser component of Google Chrome on Android allows a remote attacker to bypass system access restrictions. It is triggered by luring a user to open a crafted HTML page, as the CVSS vector requires user interaction (UI:R). A successful attacker gains unauthorized access to restricted functionality, scored as a high impact to integrity with no direct confidentiality or availability impact. Only Chrome on Android versions prior to 153.0.8010.36 are affected; the advisory does not indicate impact to desktop or other platforms. Exploitation is not confirmed in the wild: the flaw is not in CISA KEV, EPSS predicts only a 0.3% chance of exploitation within 30 days, and the sole public reference is the Chromium issue-tracker entry (issues.chromium.org/issues/520201931).

What to do: Update Chrome on Android to version 153.0.8010.36 or later (Settings > About Chrome, or via Google Play) and verify that managed Android fleets have received the update. Until patched, avoid opening HTML pages or links from untrusted sources in Chrome on Android, since exploitation requires user interaction.

Affected
google chromeGoogle Chrome on Android prior to 153.0.8010.36
Estimated exposure
mass≈1–3 billion Chrome-on-Android users on builds before 153.0.8010.36 — Chrome is the preinstalled or primary browser on the roughly 3-billion-strong active Android device base and is updated via Google Play, so effectively the entire Chrome-on-Android population running builds before 153.0.8010.36 is exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.