ZeroHour

CVE-2026-87534

mass

Missing Authorization in Google Chrome WebView on Android (CVE-2026-87534)

CVSS 3.1
9.8 critical
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-87534 is a missing-authorization flaw (CWE-862) in the WebView component of Google Chrome on Android, fixed in Chrome 153.0.8010.36. A remote attacker triggers it by combining crafted network traffic with social engineering — i.e., persuading the user into an action — which allows the attacker to bypass system access restrictions enforced around WebView content. Successful exploitation undermines permission boundaries on the device, with high potential confidentiality and integrity impact per the CVSS vector, although Google rates it only Medium severity and user interaction is required. Affected users are those running Chrome on Android prior to 153.0.8010.36; no other platforms are indicated in the advisory. There is no evidence of active exploitation: the flaw is not in CISA KEV, no public PoC is known, and EPSS is just 0.2% (7th percentile) over the next 30 days.

What to do: Update Chrome on Android to 153.0.8010.36 or later via Google Play (or confirm auto-updates are enabled) and verify the running version at chrome://version; enterprise admins should push the updated package via MDM. Until patched, treat unsolicited links and prompts with extra caution, since exploitation requires social engineering in combination with crafted network traffic.

Affected
google chromeChrome on Android prior to 153.0.8010.36 (WebView component)
Estimated exposure
mass≈1 billion+ Chrome-for-Android users (dominant Android browser, billions of installs) — Chrome is the default/dominant browser on Android with billions of active users, so nearly every unpatched Android device running Chrome fell within the affected range until the 153.0.8010.36 update rolled out.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.