Junglewise Threat Intelligence

CVE-2026-87503: Google Chrome inappropriate implementation in Downloads on Android

CVE-2026-87503 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android contains a flaw in its Downloads feature that allows attackers to bypass system access restrictions through social engineering. An attacker can craft a malicious HTML page that, when opened by a user, circumvents the browser's safety controls, potentially leading to unauthorized file downloads or system access on the victim's device.

Technical details

This vulnerability is an inappropriate implementation flaw in the Downloads component of Google Chrome on Android. The vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page, requiring user interaction (social engineering/visiting a malicious page). The attack is network-accessible and does not require authentication. An attacker can exploit this to circumvent security controls that normally prevent unauthorized downloads or system access. The vulnerability was patched in Chrome version 153.0.8010.36 for Android.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats