Executive brief
Google Chrome's Download feature contained a missing authorization check that allowed remote attackers to bypass system access restrictions. An attacker could exploit this vulnerability via a crafted Chrome extension, potentially gaining unauthorized access to system resources that should normally be protected from web content.
Technical details
This vulnerability is a missing authorization issue in Chrome's Downloads component (CVE-2026-87441, severity: Medium, CVSS 6.5). The vulnerability allows a remote attacker to bypass system access restrictions by submitting a specially crafted Chrome extension. The attack vector is network-based and requires no authentication, though user installation of the malicious extension is a precondition. An attacker can leverage this to escape the normal sandbox restrictions and access system resources inappropriately. The vulnerability was fixed in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released