4
CVE-2026-87486
- EPSS 0.12%
- Veröffentlicht 09.09.2026 00:09:50
- Zuletzt bearbeitet 10.09.2026 19:15:19
- Erkennungen
Clickjacking in TrustedWebActivities in Google Chrome on on Android prior to 153.0.8010.36 allowed a local attacker to spoof address bar via a co-installed app. (Chromium security severity: Medium)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.021 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4 | 1.4 | 2.5 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
https://issues.chromium.org/issues/514017067