Junglewise Threat Intelligence

CVE-2026-87452: Google Chrome incorrect authorization in GPU on Mac

CVE-2026-87452 · Severity: low · CVSS 3.1 · Published 2026-09-09

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome on Mac contains an authorization flaw in its GPU (graphics processing) component. An attacker who has already compromised a webpage's rendering process could exploit this to access sensitive data from other websites, potentially exposing user information that should be isolated between different origins.

Technical details

This vulnerability is an incorrect authorization flaw in the GPU component of Google Chrome on macOS. The attack requires an attacker to have already compromised the renderer process, which is a sandboxed component responsible for executing website code. The attacker can then craft a malicious HTML page to exploit the authorization weakness and read cross-origin data that should be protected by browser security boundaries. The vulnerability was patched in Chrome version 153.0.8010.36 and later; users on macOS prior to this version are affected.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats