CVE-2026-87503
PoC massDownloads Access-Restriction Bypass in Google Chrome for Android
CVE-2026-87503 is an inappropriate implementation in the Downloads component of Google Chrome on Android, tracked as CWE-841 (improper enforcement of a behavioral workflow). An attacker must use social engineering to lure an Android user into interacting with a crafted HTML page, and the flaw then lets the attacker bypass system access restrictions tied to downloaded files. The impact is high on integrity with no confidentiality or availability impact per the CVSS vector, meaning downloaded content or system file-handling rules can be altered or circumvented rather than data being directly read. Affected users are anyone running Chrome on Android prior to 153.0.8010.36; desktop Chrome is not named in the advisory. There is one public issue-tracker reference (a Chromium bug) but no confirmed in-the-wild exploitation, and EPSS puts the 30-day exploitation probability at just 0.2% (13th percentile), consistent with its Medium severity.
What to do: Update Chrome for Android to 153.0.8010.36 or later (check chrome://version and use Play Store or enterprise MDM to force the update). Until patched, treat unexpected download prompts on web pages with suspicion and avoid granting download/file-access permissions from untrusted sites. Only the Android build is named as affected; desktop deployments do not need action based on this advisory.
| google chrome | Chrome on Android prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-841
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.