Description
Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution outside sandbox
Action: Immediate Patch
AI Analysis

Impact

Incorrect authorization in WebView on Android allows a remote attacker who has already compromised the renderer process to execute arbitrary code outside the Chrome sandbox via a crafted HTML page. This flaw means that code running in the renderer can escape the browser’s security boundaries and potentially impact other applications or the operating system. The weakness is classified as CWE‑863, indicating a failure to enforce proper authorization checks on user input or context. Based on the description, the likely attack vector involves delivering a malicious HTML page to the WebView renderer.

Affected Systems

The affected product is Google Chrome for Android. Versions earlier than 153.0.8010.36 are impacted. All Android devices running a legacy Chrome build prior to that release, especially those that expose the WebView renderer to content from untrusted sources, are susceptible.

Risk and Exploitability

Because exploitation requires prior compromise of the renderer process, the attack surface is limited to scenarios where the attacker can inject malicious web content or achieve remote code execution within the renderer. Chromium rates the vulnerability as Medium. The EPSS score indicates less than 1%, and the issue is not listed in CISA KEV. Once the renderer is compromised, the attacker can gain code execution with higher privileges, posing a significant risk. The likely attack vector involves delivering crafted HTML content to the WebView renderer process.

Generated by OpenCVE AI on September 9, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later on all affected Android devices
  • Ensure automatic updates are enabled to receive the security patch promptly
  • If an immediate update is not possible, disable or restrict any WebView components that load external untrusted content until the patch is applied

Generated by OpenCVE AI on September 9, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Incorrect Authorization in Chrome WebView on Android

Wed, 09 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Incorrect Authorization in Chrome WebView on Android

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebView in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:56:12.792Z

Reserved: 2026-09-08T22:38:17.943Z

Link: CVE-2026-87481

cve-icon Vulnrichment

Updated: 2026-09-09T14:13:05.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:04.773

Modified: 2026-09-10T04:18:21.087

Link: CVE-2026-87481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:13Z

Weaknesses