CVE-2026-87552: Medium severity Google Google Chrome vulnerability
Chromium CVE-2026-87552: Missing authorization in TrustedWebActivities
Other sources
Missing authorization in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome for Androidto a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
Who is exposed to this issue?
Android devices running Google Chrome before 153.0.8010.36 are affected. Exploitation requires a malicious or otherwise untrusted app to be co-installed on the device.
What access does an attacker need?
The attacker needs local presence through a co-installed application. The provided information does not indicate that remote web content alone can exploit the issue.
What is the remediation?
Update Google Chrome on Android to version 153.0.8010.36 or later.