Junglewise Threat Intelligence

CVE-2026-87481: Google Chrome WebView authorization bypass in Android

CVE-2026-87481 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's WebView component on Android contains an authorization flaw that allows attackers who have already compromised the browser's rendering process to break out of the security sandbox and execute arbitrary code on the device. This could lead to complete device compromise if exploited in combination with other renderer vulnerabilities.

Technical details

This is an incorrect authorization vulnerability in Chrome's WebView on Android, affecting versions prior to 153.0.8010.36. The flaw allows a remote attacker who has already compromised the renderer process to bypass sandbox restrictions via a crafted HTML page, potentially executing arbitrary code outside the sandbox. The vulnerability requires the renderer process to be already compromised, indicating it is likely a sandbox escape vulnerability used in multi-stage attacks. The fix is available in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released for Android

References

Related threats