
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87597 is a UI misrepresentation vulnerability in the CustomTabs component of Google Chrome on Android that allows a remote attacker to spoof the address bar via a co-installed application. It affects all versions of Google Chrome for Android prior to 153.0.8010.36. The issue was reported internally by Google on July 9, 2026, and publicly disclosed on September 8–9, 2026, as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 4.8 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Github Advisory).
The vulnerability is classified under CWE-451 (User Interface Misrepresentation of Critical Information) and CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). The root cause lies in how Chrome's CustomTabs feature on Android renders the address bar, allowing a co-installed malicious or compromised application to manipulate the displayed URL, causing users to believe they are visiting a legitimate site when they are not. Exploitation requires the attacker to have a co-installed app on the victim's Android device, which raises the attack complexity. The Chromium issue tracker reference is bug #533018632 (Chrome Releases, Github Advisory).
Successful exploitation enables a remote attacker to spoof the address bar displayed within a Chrome CustomTab on Android, potentially deceiving users into believing they are interacting with a trusted website. This primarily facilitates phishing attacks, where victims may submit credentials or sensitive information to attacker-controlled pages. The confidentiality impact is low (limited data exposure), there is no direct integrity impact, and availability impact is also low; lateral movement or system compromise are not direct consequences of this vulnerability (Github Advisory, Red Hat Bugzilla).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-87597. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.161% (0.00161), placing it in a low exploitation probability tier. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a co-installed app on the target Android device, significantly limiting the attacker's reach (Github Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 153.0.8010.36 for Android (and 153.0.8010.36/.37 for Windows/Mac). Users should update Google Chrome on Android to version 153.0.8010.36 or later via the Google Play Store. No specific configuration-based workaround has been published; upgrading to the patched version is the recommended and only confirmed remediation. Organizations managing Android fleets should prioritize deploying this update through their mobile device management (MDM) solutions (Chrome Releases).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."