CVE-2026-91717: Google Google Chrome vulnerability
Published Sep 15, 2026
·Updated
Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtain sensitive information via a co-installed app. (Chromium security severity: High)
Affected Software
1 affected component
Google Google Chrome<153.0.8010.47
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Android)to a version that resolves this vulnerability.Fixed in 153.0.8010.47
Event History
Sep 15, 2026
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires a local attacker using a co-installed app on an Android device running Google Chrome.
2
What could an attacker obtain?
A successful attacker could obtain sensitive information.
3
How can I determine whether a device is affected?
Check the installed Google Chrome version on Android. Versions earlier than 153.0.8010.47 are affected.