CVE-2026-87595: SSRF
Chromium CVE-2026-87595: Server-side request forgery in Mobile
Other sources
Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
Which users are exposed to this issue?
Users of Google Chrome Mobile versions earlier than 153.0.8010.36 are affected if they can be persuaded to open a crafted HTML page.
What does exploitation require?
A remote attacker needs social engineering to get the target to interact with a crafted HTML page. The reported impact is bypassing system access restrictions through server-side request forgery.
Are Chrome versions 153.0.8010.36 and later affected?
The issue is reported as affecting Google Chrome Mobile prior to version 153.0.8010.36. Updating to 153.0.8010.36 or later addresses the affected version range.