ZeroHour

CVE-2026-87595

mass

SSRF in Google Chrome for Mobile before 153.0.8010.36

CVSS 3.1
9.8 critical
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-87595 is a server-side request forgery (SSRF) flaw in Google Chrome on mobile platforms, fixed in version 153.0.8010.36. It is triggered when a victim is socially engineered into visiting a crafted HTML page, which causes the browser to issue requests that bypass system access restrictions. Successful exploitation could let a remote attacker reach or interact with resources that should be inaccessible from the victim's device context. All users of Chrome on mobile operating systems (Android/iOS) running versions prior to 153.0.8010.36 are affected. Chromium assesses the severity as Low, despite a published CVSS 3.1 score of 9.8; no public proof of concept exists and no exploitation in the wild has been reported (EPSS ~0.2%, not in CISA KEV).

What to do: Update Chrome on Android and iOS to 153.0.8010.36 or later via Google Play or the App Store, and confirm automatic updates are enabled for the browser. Enterprise administrators should verify managed mobile fleets have pulled the patched build. Weigh the vendor's Low severity rating over the externally assigned CVSS 9.8 when prioritizing, but patch promptly since exploitation requires only a user clicking a crafted link.

Affected
Google Chrome (Mobile)prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome mobile install base, majority of ~3-4 billion total Chrome users) — Chrome holds roughly 60-65% of global browser market share across billions of mobile devices, so the majority of that base runs the affected mobile builds, though auto-update channels on Android and iOS shrink the unpatched population over…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.