CVE-2026-87482: Medium severity Google Google Chrome vulnerability
Chromium CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades
Other sources
Cleartext transmission of sensitive data in HttpsUpgrades in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to leak sensitive information via crafted network traffic. (Chromium security severity: Medium)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome on iOSto a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
Which Chrome installations are affected?
Google Chrome on iOS versions prior to 153.0.8010.36 are affected. The provided information does not identify other platforms as affected.
What does an attacker need to exploit this issue?
A remote attacker needs the ability to provide crafted network traffic. The issue concerns cleartext transmission of sensitive data in HttpsUpgrades.
What is the available remediation?
Update Google Chrome on iOS to version 153.0.8010.36 or later.