SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-87595

CRITICAL · CVSS 9.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A server-side request forgery vulnerability in the Mobile version of Google Chrome prior to version 153.0.8010.36 enables remote attackers to exploit social engineering tactics to bypass system access restrictions through a specially crafted HTML page. While the Chromium security team has classified the severity as low, organizations using affected versions should prioritize updates to mitigate potential risks associated with unauthorized access. Users and administrators of Chrome should ensure they are running the latest version to protect against this vulnerability.

CVE
CVE-2026-87595
Severity
CRITICAL
CVSS
9.8
EPSS
0.31%
Chrome

Original NVD Description

Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Related CVEs

Other vulnerabilities affecting the same vendor(s)