Junglewise Threat Intelligence

CVE-2026-87522: Google Chrome missing authorization in WebView on Android

CVE-2026-87522 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's WebView component on Android contains a missing authorization vulnerability that allows a remote attacker to bypass system access restrictions. An attacker can exploit this through social engineering and crafted network traffic, potentially gaining unauthorized access to protected system features or data without proper verification of user permissions.

Technical details

The vulnerability is a missing authorization flaw in the WebView component of Google Chrome on Android prior to version 153.0.8010.36. It allows a remote attacker to bypass system access restrictions via crafted network traffic, leveraging social engineering as a precondition for successful exploitation. The attack vector is network-based. An attacker can potentially bypass security controls designed to restrict access to sensitive system features. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats