• PATCH AVAILABLE

CVE-2026-87534: missing authorization bypass in Google Chrome

A remote attacker can bypass system access restrictions in Google Chrome's WebView component, enabling access to protected functionality on affected Android installations. CVE-2026-87534 affects Chrome 153.x builds before 153.0.8010.36; the vendor fixed the issue in 153.0.8010.36. Exploitation requires sending crafted network traffic and leveraging social engineering; no account or prior authentication is required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00292
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: upgrade affected Chrome WebView instances because the flaw permits bypassing authorization without authentication, letting remote attackers act after a crafted network interaction.

What is CVE-2026-87534?

A remote attacker can bypass system access restrictions in Google Chrome's WebView component, enabling access to protected functionality on affected Android installations. CVE-2026-87534 affects Chrome 153.x builds before 153.0.8010.36; the vendor fixed the issue in 153.0.8010.36. Exploitation requires sending crafted network traffic and leveraging social engineering; no account or prior authentication is required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
153.x153.0.8010.36 – before 153.0.8010.36153.0.8010.36

Is CVE-2026-87534 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-87534

  1. Update Chrome to 153.0.8010.36 or later on affected Android devices.
  2. Apply any vendor guidance from Google for WebView hardening and configuration.
  3. Restrict exposure of devices to untrusted networks and monitor for unusual WebView network activity.

Frequently asked questions

Is CVE-2026-87534 being actively exploited?

There are no public reports of exploitation of CVE-2026-87534 as of 2026-09-29.

Which Chrome versions are affected by CVE-2026-87534?

Chrome 153.x builds before 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.

Is there a patch for CVE-2026-87534?

Yes. Google fixed the vulnerability in Chrome build 153.0.8010.36.

Does CVE-2026-87534 require authentication?

No. The issue is a missing authorization in WebView and does not require prior authentication.

References