Junglewise Threat Intelligence

CVE-2026-87436: Google Chrome web origin policy bypass in crafted extension

CVE-2026-87436 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's browser contained incomplete cleanup of extension-related state, allowing a malicious extension to bypass the web origin policy that normally prevents one website from accessing data or functionality belonging to another. An attacker could exploit this through social engineering to trick a user into installing a crafted extension, potentially exposing sensitive cross-site data or enabling unauthorized actions on behalf of the user.

Technical details

This vulnerability is a same-origin policy (SOP) bypass in Google Chrome's browser engine. The root cause is incomplete cleanup of state in the Browser component when handling Chrome extensions, allowing a crafted malicious extension to escape the intended sandboxing restrictions. An attacker must first socially engineer a user into installing the malicious extension, after which the incomplete cleanup enables the extension to bypass web origin policy protections and access cross-origin data or functionality. The vulnerability was patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats