Junglewise Threat Intelligence

CVE-2026-87441: Google Chrome missing authorization in Downloads

CVE-2026-87441 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Download feature contained a missing authorization check that allowed remote attackers to bypass system access restrictions. An attacker could exploit this vulnerability via a crafted Chrome extension, potentially gaining unauthorized access to system resources that should normally be protected from web content.

Technical details

This vulnerability is a missing authorization issue in Chrome's Downloads component (CVE-2026-87441, severity: Medium, CVSS 6.5). The vulnerability allows a remote attacker to bypass system access restrictions by submitting a specially crafted Chrome extension. The attack vector is network-based and requires no authentication, though user installation of the malicious extension is a precondition. An attacker can leverage this to escape the normal sandbox restrictions and access system resources inappropriately. The vulnerability was fixed in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats