Executive brief
Google Chrome's SafeBrowsing feature on Android contains an improper input validation vulnerability that allows a remote attacker to bypass system access restrictions through social engineering and a crafted HTML page. This could enable attackers to circumvent Chrome's built-in security protections that are designed to prevent users from accessing malicious or dangerous websites.
Technical details
The vulnerability is an improper input validation flaw in the SafeBrowsing component of Google Chrome on Android prior to version 153.0.8010.36. An attacker can exploit this by crafting a malicious HTML page and using social engineering to trick a user into visiting it, thereby bypassing system access restrictions. The vulnerability requires user interaction (clicking a link) and network reachability but does not require authentication. A successful exploit allows an attacker to bypass Chrome's SafeBrowsing protections. The vulnerability is patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36