Junglewise Threat Intelligence

CVE-2026-93384: Google Chrome server-side request forgery in Omnibox on Android

CVE-2026-93384 · Severity: low · CVSS 3.7 · Published 2026-09-17

Executive brief

Google Chrome's address bar (Omnibox) on Android contained a server-side request forgery vulnerability that could allow attackers to bypass system access restrictions through specially crafted network traffic and social engineering. An attacker could potentially trick users into visiting malicious links that trigger unauthorized requests on the victim's behalf, compromising the security of their device and data.

Technical details

The vulnerability is a server-side request forgery (SSRF) flaw in the Omnibox component of Google Chrome on Android, affecting versions prior to 153.0.8010.52. The attack requires social engineering to trick a user into interacting with crafted network traffic, but does not require user authentication or local access. Successful exploitation allows an attacker to bypass system access restrictions by making requests that appear to originate from the user's device. The vulnerability was patched in Chrome 153.0.8010.52 released on September 17, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.52 on Android

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Chrome 153.0.8010.52 released

References

Related threats