MEDIUM
chromium-browser: chromium-browser: Clickjacking in TrustedWebActivities
Published Sep 9, 2026
4.0
MEDIUMCVSS 3.1
EPSS 0.11%
Description
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
Affected products
-
- Version 153.0.8010.36StatusaffectedConstraints<153.0.8010.36
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2026-87486 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2530350 Issue Tracking
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-74368 Advisory
- https://issues.chromium.org/issues/514017067 ExploitIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2026-87486
- https://www.cve.org/CVERecord?id=CVE-2026-87486
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-87486 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2530350 | Issue Tracking | |
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-74368 | Advisory | |
| https://issues.chromium.org/issues/514017067 | ExploitIssue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-87486 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-87486 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Sep 9, 2026
Updated Sep 9, 2026
Reserved Sep 8, 2026
Link CVE-2026-87486
CISA Vulnrichment
Updated Sep 9, 2026
ENISA EUVD
EUVD-2026-74368 Assigner Chrome
Published Sep 9, 2026
Updated Sep 9, 2026
Exploited since n/a
Link EUVD-2026-74368