ZeroHour

CVE-2026-87503

PoC mass

Downloads Access-Restriction Bypass in Google Chrome for Android

CVSS 3.1
6.5 medium
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-87503 is an inappropriate implementation in the Downloads component of Google Chrome on Android, tracked as CWE-841 (improper enforcement of a behavioral workflow). An attacker must use social engineering to lure an Android user into interacting with a crafted HTML page, and the flaw then lets the attacker bypass system access restrictions tied to downloaded files. The impact is high on integrity with no confidentiality or availability impact per the CVSS vector, meaning downloaded content or system file-handling rules can be altered or circumvented rather than data being directly read. Affected users are anyone running Chrome on Android prior to 153.0.8010.36; desktop Chrome is not named in the advisory. There is one public issue-tracker reference (a Chromium bug) but no confirmed in-the-wild exploitation, and EPSS puts the 30-day exploitation probability at just 0.2% (13th percentile), consistent with its Medium severity.

What to do: Update Chrome for Android to 153.0.8010.36 or later (check chrome://version and use Play Store or enterprise MDM to force the update). Until patched, treat unexpected download prompts on web pages with suspicion and avoid granting download/file-access permissions from untrusted sites. Only the Android build is named as affected; desktop deployments do not need action based on this advisory.

Affected
google chromeChrome on Android prior to 153.0.8010.36
Estimated exposure
mass≈ billions of Android devices (Chrome has 10B+ Play Store installs and ~65% mobile browser share) — Chrome is the default and dominant browser on Android, with billions of active installations worldwide, so effectively the entire Chrome-on-Android fleet below the fixed build is plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Inappropriate implementation in Downloads in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-841
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.