External risk intelligence

Google Chrome Mobile SSRF via Crafted HTML

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-87595

This vulnerability affects the mobile version of a web browser and requires social engineering to execute via a crafted HTML page. It is a client-side interaction typically initiated by a user rather than a public-facing service, gateway, or edge infrastructure that is reachable from the internet.

Server-Side Request Forgery

Google Chrome

before 153.0.8010.36

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a security flaw identified in the mobile version of Google Chrome that could allow attackers to bypass access restrictions. While the technical risk is considered low, the method of exploitation involves social engineering via a crafted webpage, making it important to understand its potential relevance to our user base.

  • Flaw bypasses access restrictions in Chrome mobile.
  • Attackers use social engineering with fake web pages.
  • Confirm relevance and user exposure to the risk.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious HTML page, which could then cause the vulnerable browser component to make unintended requests on the server. This bypasses security restrictions and could lead to sensitive information disclosure, data manipulation, or denial of service.

  • User must visit a crafted page.
  • Malicious HTML page triggers vulnerability.
  • Bypass system access restrictions.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a remote attacker leveraging social engineering could bypass system access restrictions by tricking a user into interacting with a crafted HTML page. This could potentially expose sensitive information or affect service behavior.

  • System access restrictions may be bypassed.
  • User interaction with a crafted HTML page.
  • Information disclosure or service disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Google Chrome on mobile devices, requiring social engineering to exploit. The first step is to identify any mobile Chrome instances that might be exposed to crafted HTML pages. System owners should then determine if these instances are business-critical and confirm the accountable team, whether it's the application owner, platform team, or mobile device management.

  • Confirm mobile Chrome exposure and ownership.
  • Verify business criticality and user impact.
  • Plan remediation or mitigation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome Mobile?

Google Chrome Mobile is a web browser application used on smartphones and tablets to access the internet. It handles the complex process of rendering web pages, executing scripts, and managing network requests on behalf of the user to provide a seamless browsing experience.

What does CVE-2026-87595 mean for browser security?

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability, classified as CWE-918. It means the browser can be manipulated to make unauthorized network requests to internal resources or services it should not normally access, potentially exposing data or altering system behavior.

How does an attacker trigger this vulnerability?

An attacker must successfully use social engineering to convince a user to navigate to a specifically crafted HTML page. Simply viewing an ordinary, legitimate website does not trigger this flaw, as it requires the browser to process the malicious code embedded in the attacker-controlled page.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal considers this risk 'Very unlikely' because the flaw is in a mobile browser and requires active user interaction via social engineering. It is not an automated attack against a public-facing server or internet-accessible gateway, which limits its practical scope.

What steps should I take if I use Chrome on mobile?

First, verify that your mobile browser is updated to the latest available version provided by the official app store. Beyond updates, maintain awareness of suspicious links and avoid visiting untrusted websites, as the vulnerability relies on you interacting with malicious HTML content.

References