CVE-2026-87486
Chromium CVE-2026-87486: Clickjacking in TrustedWebActivities
mediumEPSS 0.1%
Affected
- google/chrome
lt *..153.0.8010.36
Description
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
Affected operating systems
linux
debian / chromiumtrixie
Metrics
Show all metrics
Severity
medium
50.01
no public PoC known
4.0
Published
2026-09-30 20:26 UTC
CWE-1021
Weakness classes (CWE)
CWE-1021Base
Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-10 19:15 UTC· nvd@nist.gov
- CPE Configuration: AND OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.36 OR cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
- Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html Types: Release Notes, Vendor Advisory
- Reference Type: Chrome: https://issues.chromium.org/issues/514017067 Types: Exploit, Issue Tracking, Patch
- New CVE Received2026-09-09 01:17 UTC· chrome-cve-admin@google.com
- Description: Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
- CWE: CWE-1021
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/87xxx/CVE-2026-87486.json">CVE-2026-87486</a>
- Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html