CVE-2026-87463: Medium severity Google Google Chrome on Android vulnerability
Chromium CVE-2026-87463: Incorrect authorization in Certificate
Other sources
Incorrect authorization in Certificate in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to potentially spoof address bar via crafted network traffic. (Chromium security severity: Low)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.8010.36Patch CVE-2026-87463
Event History
Frequently Asked Questions
Which deployments are affected?
Google Chrome on Android versions prior to 153.0.8010.36 are affected. The provided data does not identify any affected desktop or non-Android Chrome versions.
What does an attacker need to exploit this issue?
The issue can be triggered by crafted network traffic from a remote attacker. The provided data does not state that authentication, local access, or user interaction is required.
What is the potential impact?
A successful attack could potentially spoof the browser address bar, which may make a site appear to have a different address than it actually does.
How can I determine whether remediation is needed?
Check the installed Chrome version on affected Android devices. Devices running a version earlier than 153.0.8010.36 require an update.