Description
Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Immediately
AI Analysis

Impact

The vulnerability is an incorrect authorization check in Google Chrome for Android that allows a crafted HTML page to bypass system access restrictions, enabling an attacker to elevate privileges from a regular user to a higher level and undermine device security. This flaw is identified as CWE-863 (Authorization Bypass for Local Privilege Escalation).

Affected Systems

Devices running Google Chrome for Android earlier than version 153.0.8010.36 are affected. The issue applies to all Android models that ship with the affected Chrome package version, and no other platforms or browsers are mentioned.

Risk and Exploitability

The CVE has a CVSS score of 6.5, rating it as medium severity, and is not listed in the CISA KEV catalog. EPSS score is < 1%, indicating a very low but non-zero exploitation likelihood; the precise likelihood of exploitation remains unknown. The vulnerability can be triggered by a remote attacker who lures the victim to a malicious webpage. The exploitation requires the victim to load the crafted page in Chrome, making it a client‑side attack that could compromise device security if the user visits a malicious site.

Generated by OpenCVE AI on September 10, 2026 at 16:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 153.0.8010.36 or newer
  • If upgrading is not immediately possible, consider uninstalling or disabling Chrome until an update is available
  • Use a trusted or updated browser and enforce safe browsing filters to block malicious URLs

Generated by OpenCVE AI on September 10, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome

Thu, 10 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Crafted HTML Page in Chrome on Android

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass via Crafted HTML Page in Chrome on Android

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Browser in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T14:04:19.383Z

Reserved: 2026-09-08T22:38:20.521Z

Link: CVE-2026-87483

cve-icon Vulnrichment

Updated: 2026-09-10T14:03:49.040Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:04.990

Modified: 2026-09-10T19:16:14.973

Link: CVE-2026-87483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:00:06Z

Weaknesses