Description
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Clickjacking enabling phishing in Chrome Android
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a clickjacking flaw in TrustedWebActivities on Google Chrome for Android. A local attacker can use a co‑installed app to display a fake address bar, tricking users into believing they are viewing a legitimate webpage. The attacker could then perform phishing or other malicious actions while the user thinks they are interacting with Chrome. This weakness is classified as CWE‑1021.

Affected Systems

Google Chrome on Android devices running versions earlier than 153.0.8010.36 are affected. The issue specifically targets TrustedWebActivities that allow apps to replace or overlay Chrome’s UI elements.

Risk and Exploitability

The CVSS score of 4.0 indicates a medium severity impact. The EPSS score is less than 1 percent, suggesting a low likelihood of exploitation, and this vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a local co‑installed application that overlays the Chrome UI and can spoof the address bar. It is inferred the attacker would need permissions to draw over other apps. The vulnerability could lead to user deception or credential theft, but no widespread exploitation has been reported. The overall impact is considered moderate.

Generated by OpenCVE AI on September 9, 2026 at 21:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or newer on all Android devices.
  • If an upgrade is not yet available, disable the TrustedWebActivities feature or uninstall any applications that can modify Chrome’s UI, if your device allows such settings.
  • Limit app installations to trusted sources only and review permissions for installed applications, particularly those that request UI overlay or notification permissions.

Generated by OpenCVE AI on September 9, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Clickjacking in TrustedWebActivities Spoofing Chrome Address Bar

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Clickjacking in TrustedWebActivities Spoofing Chrome Address Bar

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
Weaknesses CWE-1021
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:44:41.023Z

Reserved: 2026-09-08T22:38:24.658Z

Link: CVE-2026-87486

cve-icon Vulnrichment

Updated: 2026-09-09T19:42:21.263Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:05.330

Modified: 2026-09-10T19:15:19.133

Link: CVE-2026-87486

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:15:17Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames