• PATCH AVAILABLE

CVE-2026-87595: server-side request forgery in Google Chrome

A remote attacker can induce Google Chrome Mobile to perform server-side requests and bypass system access restrictions by convincing a user to load a crafted HTML page. CVE-2026-87595 affects Chrome 153.x builds before 153.0.8010.36; the vendor fixed the issue in 153.0.8010.36. Exploitation requires social engineering to get a user to open the malicious page in the affected browser build.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00419
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgently update affected Chrome Mobile installs to 153.0.8010.36 because a remote SSRF can be triggered via a crafted page without prior authentication and a vendor fix is available.

What is CVE-2026-87595?

A remote attacker can induce Google Chrome Mobile to perform server-side requests and bypass system access restrictions by convincing a user to load a crafted HTML page. CVE-2026-87595 affects Chrome 153.x builds before 153.0.8010.36; the vendor fixed the issue in 153.0.8010.36. Exploitation requires social engineering to get a user to open the malicious page in the affected browser build. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
153.x153.0.8010.36 – before 153.0.8010.36153.0.8010.36

Is CVE-2026-87595 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-87595

  1. Upgrade Chrome Mobile to 153.0.8010.36 or later.
  2. Block untrusted content and reduce exposure of internal resources to the browser where possible.
  3. Monitor browser logs and network requests for unexpected server-side request patterns.
  4. Follow Google’s guidance for enterprise deployments to deploy the update widely and promptly.

Frequently asked questions

Is CVE-2026-87595 being actively exploited?

There are no public reports of exploitation as of 2026-09-29.

Which Chrome versions are affected by CVE-2026-87595?

Chrome 153.x builds before 153.0.8010.36 are affected; the flaw is fixed in 153.0.8010.36.

Is there a patch for CVE-2026-87595?

Yes, Google fixed the issue in Chrome version 153.0.8010.36.

Does CVE-2026-87595 require authentication?

No, exploitation relies on social engineering to get a user to open a crafted HTML page and does not require prior authentication.

References