Microsoft Security Response Center guidance
Release Notes
Vendor-listed releases
- 153.0.4234.32
Vulnerability intelligence
CVE-2026-87595 and is rated Critical severity with a CVSS score of 9.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
Server-side request forgery in Mobile in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)