Description
Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via SafeBrowsing bypass
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper input validation flaw in Google Chrome’s SafeBrowsing feature on Android devices. A crafted HTML page can trick a remote attacker into bypassing normal system access restrictions, potentially granting elevated privileges. The described defect is categorized under CWE‑20 and has a medium severity rating by Chromium security.

Affected Systems

Android installations of Google Chrome with versions earlier than 153.0.8010.36 are affected. Users on these releases are at risk if they visit malicious or social‑engineering webpages that exploit this flaw.

Risk and Exploitability

The exploit requires a remote attacker to supply a specially crafted HTML page to a target device, leveraging social engineering. The EPSS score is <1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 rates the vulnerability as moderate, showing that while the attack’s impact could be significant, it requires user interaction and is not trivially automated. If unpatched, attackers could use this path to elevate privileges or access protected resources.

Generated by OpenCVE AI on September 10, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 153.0.8010.36 or later on all Android devices.
  • If an immediate update is not possible, temporarily disable the SafeBrowsing protection to prevent the specific bypass while maintaining other security controls.
  • Continuously monitor user education and awareness programs to reduce success of social‑engineering phishing attempts until the patch is applied.

Generated by OpenCVE AI on September 10, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Fri, 11 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Fri, 11 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title SafeBrowsing Input Validation Flaw Enabling Privilege Escalation on Android Chrome

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title SafeBrowsing Input Validation Flaw Enabling Privilege Escalation on Android Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T14:38:10.934Z

Reserved: 2026-09-08T22:41:59.326Z

Link: CVE-2026-87600

cve-icon Vulnrichment

Updated: 2026-09-10T14:37:38.111Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:18.010

Modified: 2026-09-11T13:57:19.077

Link: CVE-2026-87600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:00:08Z

Weaknesses
  • CWE-20

    Improper Input Validation