Junglewise Threat Intelligence

CVE-2026-87552: Google Chrome missing authorization in TrustedWebActivities on Android

CVE-2026-87552 · Severity: medium · CVSS 5.5 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome on Android contains a flaw in TrustedWebActivities (a feature that integrates web content with native Android apps) that fails to properly verify user authorization. A local attacker who can install a malicious app on the same device could exploit this to access sensitive information that the user has shared with trusted web apps, potentially compromising personal data or credentials.

Technical details

The vulnerability is a missing authorization check in the TrustedWebActivities component of Google Chrome on Android. The flaw allows a co-installed local application to bypass authorization controls and obtain sensitive information accessible through trusted web activities. The attack requires local access (a second app installed on the device) and does not require network interaction or user authentication. An attacker can leverage this to read sensitive data that would normally be restricted to authorized web contexts. The issue is fixed in Chrome version 153.0.8010.36 and later for Android.

Affected products

  • Google Chrome Android prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats