CRITICAL 9.8 NVD
CVE-2026-87534
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system
Missing authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Affected Products
- google/android
- google/chrome
References
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027
- https://issues.chromium.org/issues/513134173
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-09 via NVD. Affected: google/android, google/chrome.
Risk Timeline
CVE Disclosed2026-09-09 · 1 day ago
Remediation Resources
Analysis & PoC
issues.chromium.org/issues/513134173Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-87544 | Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 al | CRITICAL | 9.8 |
| CVE-2026-87438 | Out of bounds write in WebGL in Google Chrome on on Android prior to 153.0.8010. | CRITICAL | 9.6 |
| CVE-2026-87448 | Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a rem | CRITICAL | 9.6 |
| CVE-2026-87455 | Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote | CRITICAL | 9.6 |
| CVE-2026-87464 | Use after free in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote | CRITICAL | 9.6 |
| CVE-2026-87474 | Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a rem | CRITICAL | 9.6 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.