CVE-2026-87595

NONE EPSS 0.18%
Updated Sep 09, 2026
Google
Parameter Value
Affected Versions before 153.0.8010.36
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Google
Public PoC No

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)