Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-87597
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-87597 is a UI misrepresentation vulnerability in the CustomTabs component of Google Chrome on Android that allows a remote attacker to spoof the address bar via a co-installed application. It affects all versions of Google Chrome for Android prior to 153.0.8010.36. The issue was reported internally by Google on July 9, 2026, and publicly disclosed on September 8–9, 2026, as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 4.8 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Github Advisory).

Technical details

The vulnerability is classified under CWE-451 (User Interface Misrepresentation of Critical Information) and CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). The root cause lies in how Chrome's CustomTabs feature on Android renders the address bar, allowing a co-installed malicious or compromised application to manipulate the displayed URL, causing users to believe they are visiting a legitimate site when they are not. Exploitation requires the attacker to have a co-installed app on the victim's Android device, which raises the attack complexity. The Chromium issue tracker reference is bug #533018632 (Chrome Releases, Github Advisory).

Impact

Successful exploitation enables a remote attacker to spoof the address bar displayed within a Chrome CustomTab on Android, potentially deceiving users into believing they are interacting with a trusted website. This primarily facilitates phishing attacks, where victims may submit credentials or sensitive information to attacker-controlled pages. The confidentiality impact is low (limited data exposure), there is no direct integrity impact, and availability impact is also low; lateral movement or system compromise are not direct consequences of this vulnerability (Github Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-87597. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The EPSS score is approximately 0.161% (0.00161), placing it in a low exploitation probability tier. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a co-installed app on the target Android device, significantly limiting the attacker's reach (Github Advisory, Chrome Releases).

Exploitation steps

  1. Prerequisite — Co-installed App: The attacker must have a malicious or attacker-controlled application already installed on the target Android device, as exploitation requires interaction between the co-installed app and Chrome's CustomTabs API.
  2. Trigger CustomTab: The malicious app opens a Chrome CustomTab session, which is a common pattern used by legitimate apps to display web content within a browser-like interface.
  3. Spoof Address Bar: The attacker leverages the UI misrepresentation flaw in CustomTabs to display a falsified URL in the address bar, making the victim believe they are visiting a trusted domain (e.g., a banking or authentication page).
  4. Phishing/Credential Harvesting: The victim, trusting the spoofed address bar, interacts with the attacker-controlled web content — potentially submitting credentials, authentication tokens, or other sensitive information (Chrome Releases, Github Advisory).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 153.0.8010.36 for Android (and 153.0.8010.36/.37 for Windows/Mac). Users should update Google Chrome on Android to version 153.0.8010.36 or later via the Google Play Store. No specific configuration-based workaround has been published; upgrading to the patched version is the recommended and only confirmed remediation. Organizations managing Android fleets should prioritize deploying this update through their mobile device management (MDM) solutions (Chrome Releases).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 153.0.8010.47-1

Fixed

sid

chromium: 153.0.8010.47-1

Fixed

trixie

chromium: 153.0.8010.47-2~deb13u1

Fixed

SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93385MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93386MEDIUM5.4
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93387MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 17, 2026
CVE-2026-93383MEDIUM4.3
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026
CVE-2026-93384LOW3.7
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management