Junglewise Threat Intelligence

CVE-2026-87486: Google Chrome clickjacking in TrustedWebActivities on Android

CVE-2026-87486 · Severity: medium · CVSS 4 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome on Android includes a feature called TrustedWebActivities that allows apps to display web content. A clickjacking vulnerability in this feature permits a malicious app installed alongside Chrome to spoof the address bar, deceiving users into believing they are visiting a legitimate website when they are actually on a fraudulent one. This could lead to credential theft, malware installation, or other social engineering attacks.

Technical details

The vulnerability is a clickjacking issue in Google Chrome's TrustedWebActivities feature on Android. A local attacker with the ability to install a co-installed app can exploit this flaw to spoof the browser's address bar, potentially tricking users into entering sensitive information or downloading malicious content. The vulnerability requires local access (co-installed app) and no user authentication, but does depend on social engineering to succeed. The issue is fixed in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats