Executive brief
Google Chrome for Android contains an authorization bypass vulnerability that allows attackers to circumvent system access restrictions through a specially crafted web page. An attacker could exploit this by tricking users into visiting a malicious website, potentially gaining unauthorized access to system resources or sensitive functions normally protected from web content.
Technical details
This vulnerability is an incorrect authorization flaw in the Browser component of Google Chrome on Android versions prior to 153.0.8010.36. The vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page. The attack requires user interaction (visiting a malicious page) but no additional authentication. A successful exploit could allow an attacker to access restricted system resources or APIs that should not be accessible to web content. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released