Executive brief
Google Chrome on Android contains a flaw in how it validates website certificates that could allow an attacker to spoof the address bar—making a malicious website appear legitimate to users. An attacker could exploit this through crafted network traffic to deceive users into thinking they're visiting a trusted site, potentially leading to credential theft or malware infection.
Technical details
This is an incorrect authorization vulnerability in Chrome's certificate handling on Android. The vulnerability allows a remote attacker to craft malicious network traffic that bypasses certificate validation checks, enabling address bar spoofing where a fake website appears to come from a legitimate domain. Attack vectors are network-based and require no authentication or user interaction beyond the user navigating to the attacker's site. An attacker can deceive users into divulging credentials or installing malware by impersonating legitimate services. The vulnerability affects Chrome on Android prior to version 153.0.8010.36, which includes the fix.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed: CVE-2026-87463 publicly disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36