Description
Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Address bar spoofing
Action: Apply patch
AI Analysis

Impact

Incorrect authorization in Chrome’s certificate handling on Android before 153.0.8010.36 permits a remote attacker to spoof the browser’s address bar using crafted network traffic. This flaw allows forged addresses to appear as if they belong to legitimate sites.

Affected Systems

Google Chrome for Android versions earlier than 153.0.8010.36 are affected. Users running these builds should update to a newer release to mitigate the spoofing risk.

Risk and Exploitability

The vulnerability is identified by CWE‑863 and has a CVSS score of 4.8, indicating a low risk level. The EPSS score is <1%, suggesting a very low exploitation probability, and it is not listed in the CISA KEV catalog, indicating limited known exploitation. An attacker with network access can inject crafted packets or modify responses to trigger the incorrect authorization, allowing the spoofed address bar to appear. The low exploitation effort and lack of privileged prerequisites suggest that the risk is primarily to users who may be deceived while browsing on affected Chrome installations.

Generated by OpenCVE AI on September 9, 2026 at 22:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later
  • If an update is not possible, disable or uninstall Chrome to prevent the spoofing
  • Enable automatic updates or monitor release notes to ensure the issue is patched

Generated by OpenCVE AI on September 9, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Address Bar Spoofing in Chrome Android via Incorrect Certificate Authorization

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Address Bar Spoofing in Chrome Android via Incorrect Certificate Authorization

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:40:50.341Z

Reserved: 2026-09-08T22:37:44.052Z

Link: CVE-2026-87463

cve-icon Vulnrichment

Updated: 2026-09-09T19:40:42.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:02.790

Modified: 2026-09-09T20:31:23.793

Link: CVE-2026-87463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:30:07Z

Weaknesses