Description
Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

A crafted HTML page can trigger Google Chrome on Android (versions prior to 153.0.8010.36) to expose stored password data to a remote attacker. The vulnerability involves an information leak (CWE-200) where the browser fails to isolate or protect credentials from malicious content. The compromised data includes usernames and passwords that may allow credential‑based attacks against user accounts, but the flaw does not affect the integrity or availability of the browser or the device.

Affected Systems

Google Chrome for Android versions older than 153.0.8010.36. The issue is limited to the Android platform and does not affect other operating systems or browsers.

Risk and Exploitability

Chromium assigns a low severity to this issue, indicating that an attacker must deliver a malicious HTML page and rely on the user visiting that page. No privileges or additional credentials are required. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, exposure of credentials is a serious concern for users of affected versions.

Generated by OpenCVE AI on September 9, 2026 at 19:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 153.0.8010.36 or later on all devices.
  • Enforce the update on managed devices via enterprise policy and configure Chrome to block autofill of passwords from untrusted origins.
  • After updating, clear any cached passwords that may have been exposed by the old build.

Generated by OpenCVE AI on September 9, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Information Leak via Crafted HTML Page Exposing Stored Passwords in Chrome for Android

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google
Google android
Google chrome

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Information Leak via Crafted HTML Page Exposing Stored Passwords in Chrome for Android

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Information leak in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T15:05:13.256Z

Reserved: 2026-09-08T22:40:57.360Z

Link: CVE-2026-87565

cve-icon Vulnrichment

Updated: 2026-09-09T15:04:16.295Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:14.193

Modified: 2026-09-09T19:18:23.887

Link: CVE-2026-87565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:59:14Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor