Executive brief
Google Chrome's mobile component contains a server-side request forgery vulnerability that could allow an attacker to bypass system access restrictions. An attacker could exploit this through a crafted HTML page combined with social engineering to potentially access restricted resources or bypass security controls.
Technical details
This vulnerability is a server-side request forgery (SSRF) flaw in the Mobile component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker to bypass system access restrictions by crafting a malicious HTML page and leveraging social engineering to trick a user into visiting it. The attack requires user interaction (visiting the crafted page) but does not require prior authentication. While Chromium classified this as "Low" severity, the reported CVSS score of 9.8 suggests a critical impact potential. A patch was released in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released