CVE-2026-87483
PoC massIncorrect Authorization in Chrome for Android Bypasses System Access Restrictions
An incorrect authorization flaw (CWE-863) in the Browser component of Google Chrome on Android allows a remote attacker to bypass system access restrictions. It is triggered by luring a user to open a crafted HTML page, as the CVSS vector requires user interaction (UI:R). A successful attacker gains unauthorized access to restricted functionality, scored as a high impact to integrity with no direct confidentiality or availability impact. Only Chrome on Android versions prior to 153.0.8010.36 are affected; the advisory does not indicate impact to desktop or other platforms. Exploitation is not confirmed in the wild: the flaw is not in CISA KEV, EPSS predicts only a 0.3% chance of exploitation within 30 days, and the sole public reference is the Chromium issue-tracker entry (issues.chromium.org/issues/520201931).
What to do: Update Chrome on Android to version 153.0.8010.36 or later (Settings > About Chrome, or via Google Play) and verify that managed Android fleets have received the update. Until patched, avoid opening HTML pages or links from untrusted sources in Chrome on Android, since exploitation requires user interaction.
| google chrome | Google Chrome on Android prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.