ZeroHour

CVE-2026-87486

PoC mass

Clickjacking in Google Chrome for Android Allows Address Bar Spoofing

CVSS 3.1
4.0 medium
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2026-87486 is a clickjacking flaw (CWE-1021) in the Trusted Web Activities feature of Google Chrome on Android that lets a local attacker spoof the browser's address bar. It is triggered when a co-installed app on the same Android device interacts with a Trusted Web Activity in Chrome versions prior to 153.0.8010.36, exploiting improper restriction of rendered UI layers. A successful attack misleads the user about which site or origin is loaded, enabling UI spoofing useful for phishing; impact is modest, consistent with the CVSS 3.1 score of 4.0 (local attack, high complexity, low confidentiality/availability impact). Only Android users of Chrome prior to 153.0.8010.36 are affected; desktop Chrome and other platforms are not listed. No in-the-wild exploitation is reported (EPSS 0.2%, not in CISA KEV), but a public proof-of-concept reference exists in the Chromium issue tracker.

What to do: Update Chrome on Android to 153.0.8010.36 or later via Google Play. Because exploitation requires a malicious co-installed app, review and remove untrusted apps on shared or managed Android devices. Desktop Chrome and other platforms are unaffected.

Affected
Google Chrome (Android)Android versions prior to 153.0.8010.36
Estimated exposure
mass≈1 billion+ Chrome-for-Android installations (Chrome's Android install base) — Chrome is the dominant browser on Android with a multi-billion device install base, though real-world exploitability is narrower because it requires a malicious co-installed app on the device.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-1021
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.