CVE-2026-87534
massMissing Authorization in Google Chrome WebView on Android (CVE-2026-87534)
CVE-2026-87534 is a missing-authorization flaw (CWE-862) in the WebView component of Google Chrome on Android, fixed in Chrome 153.0.8010.36. A remote attacker triggers it by combining crafted network traffic with social engineering — i.e., persuading the user into an action — which allows the attacker to bypass system access restrictions enforced around WebView content. Successful exploitation undermines permission boundaries on the device, with high potential confidentiality and integrity impact per the CVSS vector, although Google rates it only Medium severity and user interaction is required. Affected users are those running Chrome on Android prior to 153.0.8010.36; no other platforms are indicated in the advisory. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public PoC is known, and EPSS is just 0.2% (7th percentile) over the next 30 days.
What to do: Update Chrome on Android to 153.0.8010.36 or later via Google Play (or confirm auto-updates are enabled) and verify the running version at chrome://version; enterprise admins should push the updated package via MDM. Until patched, treat unsolicited links and prompts with extra caution, since exploitation requires social engineering in combination with crafted network traffic.
| google chrome | Chrome on Android prior to 153.0.8010.36 (WebView component) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.