Google Chrome for Android WebView Authorization Bypass (CVE-2026-87534)
First seen Sep 11, 2026 · Updated Sep 11, 2026 · CVSS 9.8
A missing authorization vulnerability in WebView on Google Chrome for Android prior to version 153.0.8010.36 allows a remote attacker to bypass system access restrictions via crafted network traffic combined with social engineering. Google/Chromium rates this as Medium severity, indicating exploitation requires user interaction and does not grant full system compromise on its own.
Technical Analysis
CVE-2026-87534 stems from a missing authorization check in the WebView component of Chrome on Android, allowing crafted network traffic to circumvent intended access restrictions when a user is socially engineered into triggering the flawed code path. Because WebView is embedded in countless third-party Android apps, this could enable unauthorized access to app-level resources or data exposed through the browser rendering engine, though the Chromium team classifies it as Medium severity rather than critical, suggesting limited standalone impact without chaining to other bugs. Note the reported CVSS score of 9.8 appears inconsistent with the vendor's 'Medium' severity classification, which should be independently verified against the official Chromium security bulletin before prioritization. Exploitation vectors likely involve malicious or compromised web content loaded within a WebView-hosted app that lures a user into an interaction (e.g., clicking a link or button) to trigger the bypass. For AI agent systems, mobile or embedded agent applications that use Android WebView to render web content, display dashboards, or handle OAuth/API-key entry flows could be exposed to unauthorized data access or session hijacking if this vulnerability is exploited, particularly on devices used to manage or authenticate agent-based tooling.
Affected Systems
Google Chrome for Android, all versions prior to 153.0.8010.36; Android applications embedding vulnerable WebView versions
Indicators of Compromise
- No specific IOCs published; monitoring should focus on anomalous WebView network traffic and unexpected authorization bypass attempts within Android apps
Remediation Steps
- 1
Update Chrome/WebView
Upgrade Google Chrome on Android to version 153.0.8010.36 or later, and ensure the Android System WebView component is updated via Google Play.
- 2
Verify severity classification
Confirm the actual CVSS score and severity via the official Chromium/NVD advisory, as the reported score of 9.8 conflicts with the vendor's Medium rating.
- 3
User awareness training
Educate users on social engineering tactics that may be used to trigger this vulnerability, especially around unsolicited links or prompts within apps.
- 4
Restrict WebView usage in sensitive apps
For enterprise or agent-management applications relying on WebView for authentication or dashboard rendering, evaluate migrating to more sandboxed rendering approaches until patched.
- 5
Monitor mobile device fleets
Use MDM solutions to enforce Chrome/WebView update compliance across managed Android devices, particularly those used to access AI agent consoles or API credentials.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.