Junglewise Threat Intelligence

CVE-2026-87447: Google Chrome incorrect authorization in Network component

CVE-2026-87447 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's network component contained an authorization flaw that could allow an attacker to bypass web origin policy—a security boundary that prevents malicious websites from accessing data from other sites. An attacker could exploit this via a specially crafted Chrome extension combined with social engineering, potentially enabling unauthorized access to sensitive data across different websites.

Technical details

The vulnerability is an incorrect authorization issue in Chrome's Network component affecting versions prior to 153.0.8010.36. An attacker could bypass the same-origin policy—the critical browser security model that restricts cross-site data access—by leveraging a malicious Chrome extension and social engineering techniques. The attack requires user interaction (extension installation) but does not require authentication. Once exploited, an attacker can access data and credentials from other web origins, compromising the isolation between websites. The fix is available in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87447 published
  • 2026-09-08: patched: Fix released in Chrome 153.0.8010.36

References

Related threats