DIRAS TAKE
Urgently update affected Chrome Mobile installs to 153.0.8010.36 because a remote SSRF can be triggered via a crafted page without prior authentication and a vendor fix is available.
What is CVE-2026-87595?
A remote attacker can induce Google Chrome Mobile to perform server-side requests and bypass system access restrictions by convincing a user to load a crafted HTML page. CVE-2026-87595 affects Chrome 153.x builds before 153.0.8010.36; the vendor fixed the issue in 153.0.8010.36. Exploitation requires social engineering to get a user to open the malicious page in the affected browser build. The weakness is classified as CWE-918 (Server-Side Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 153.x | 153.0.8010.36 – before 153.0.8010.36 | 153.0.8010.36 |
Is CVE-2026-87595 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-87595
- Upgrade Chrome Mobile to 153.0.8010.36 or later.
- Block untrusted content and reduce exposure of internal resources to the browser where possible.
- Monitor browser logs and network requests for unexpected server-side request patterns.
- Follow Google’s guidance for enterprise deployments to deploy the update widely and promptly.
Frequently asked questions
Is CVE-2026-87595 being actively exploited?
There are no public reports of exploitation as of 2026-09-29.
Which Chrome versions are affected by CVE-2026-87595?
Chrome 153.x builds before 153.0.8010.36 are affected; the flaw is fixed in 153.0.8010.36.
Is there a patch for CVE-2026-87595?
Yes, Google fixed the issue in Chrome version 153.0.8010.36.
Does CVE-2026-87595 require authentication?
No, exploitation relies on social engineering to get a user to open a crafted HTML page and does not require prior authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-87595
- cve.org/CVERecord?id=CVE-2026-87595
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- issues.chromium.org/issues/513726466
- All Google CVEs on CVE Radar
- CVEs published in September 2026