CVE-2026-93384: SSRF
Published Sep 17, 2026
·Updated
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security severity: Medium)
Affected Software
1 affected component
Google Chrome for Android<153.0.8010.52
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrome (Android)to a version that resolves this vulnerability.Fixed in 153.0.8010.52
Event History
Sep 17, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Chrome for Android versions are affected?
Google Chrome for Android versions prior to 153.0.8010.52 are affected. Updating to 153.0.8010.52 or later addresses the issue.
2
What must an attacker do to exploit this vulnerability?
The attacker must use crafted network traffic and rely on social engineering. The issue is exploitable remotely and can bypass system access restrictions.