CVE-2026-87481
Google · Chrome
An incorrect authorization vulnerability in Google Chrome WebView for Android allows a remote attacker to escape the sandbox and execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity sandbox escape vulnerability in Google Chrome for Android could allow remote attackers to execute arbitrary code following a renderer process compromise.
Vulnerability
This flaw involves incorrect authorization within the WebView component, classified as CWE-863. An unauthenticated remote attacker who has successfully compromised the renderer process can bypass sandbox restrictions to execute arbitrary code on the underlying Android system.
Business impact
The ability for an attacker to escape the browser sandbox and execute arbitrary code represents a significant threat to mobile device integrity. A successful exploit could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent malicious software. While the CVSS score is 8.3, the high complexity factor mitigates the immediate risk, though the potential for total system impact necessitates prioritizing updates.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately via the Google Play Store to apply the necessary authorization fixes.
Proactive Monitoring: Monitor device security logs for unusual application behavior or unexpected process execution patterns originating from the browser environment.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to assist in detecting and blocking malicious applications that may attempt to leverage such vulnerabilities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this sandbox escape, organizations managing mobile fleets should enforce mandatory updates to Chrome version 153.0.8010.36. Vulnerabilities that allow for code execution outside of browser-based security boundaries pose a severe risk to corporate data on mobile devices, and prompt patching remains the most effective defense.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.3 (3.1)
- Analyst report written