CVE-2026-87595
massSSRF in Google Chrome for Mobile before 153.0.8010.36
CVE-2026-87595 is a server-side request forgery (SSRF) flaw in Google Chrome on mobile platforms, fixed in version 153.0.8010.36. It is triggered when a victim is socially engineered into visiting a crafted HTML page, which causes the browser to issue requests that bypass system access restrictions. Successful exploitation could let a remote attacker reach or interact with resources that should be inaccessible from the victim's device context. All users of Chrome on mobile operating systems (Android/iOS) running versions prior to 153.0.8010.36 are affected. Chromium assesses the severity as Low, despite a published CVSS 3.1 score of 9.8; no public proof of concept exists and no exploitation in the wild has been reported (EPSS ~0.2%, not in CISA KEV).
What to do: Update Chrome on Android and iOS to 153.0.8010.36 or later via Google Play or the App Store, and confirm automatic updates are enabled for the browser. Enterprise administrators should verify managed mobile fleets have pulled the patched build. Weigh the vendor's Low severity rating over the externally assigned CVSS 9.8 when prioritizing, but patch promptly since exploitation requires only a user clicking a crafted link.
| Google Chrome (Mobile) | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.