CVE-2026-87486
PoC massClickjacking in Google Chrome for Android Allows Address Bar Spoofing
CVE-2026-87486 is a clickjacking flaw (CWE-1021) in the Trusted Web Activities feature of Google Chrome on Android that lets a local attacker spoof the browser's address bar. It is triggered when a co-installed app on the same Android device interacts with a Trusted Web Activity in Chrome versions prior to 153.0.8010.36, exploiting improper restriction of rendered UI layers. A successful attack misleads the user about which site or origin is loaded, enabling UI spoofing useful for phishing; impact is modest, consistent with the CVSS 3.1 score of 4.0 (local attack, high complexity, low confidentiality/availability impact). Only Android users of Chrome prior to 153.0.8010.36 are affected; desktop Chrome and other platforms are not listed. No in-the-wild exploitation is reported (EPSS 0.2%, not in CISA KEV), but a public proof-of-concept reference exists in the Chromium issue tracker.
What to do: Update Chrome on Android to 153.0.8010.36 or later via Google Play. Because exploitation requires a malicious co-installed app, review and remove untrusted apps on shared or managed Android devices. Desktop Chrome and other platforms are unaffected.
| Google Chrome (Android) | Android versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-1021
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.