Server-Side Request Forgery (SSRF) in Google Chromium - CVE-2026-87595
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the browser to send requests to arbitrary destinations.
The vulnerability exists due to server-side request forgery in Mobile when processing crafted content. A remote attacker can trick the victim into processing crafted content to cause the browser to send requests to arbitrary destinations.
Affected software
Google Chrome
How to mitigate CVE-2026-87595
Google Chrome - update to 153.0.8010.36