Junglewise Threat Intelligence

CVE-2026-87454: Google Chrome information leak in Enterprise on Windows

CVE-2026-87454 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Executive brief

Google Chrome contains an information disclosure vulnerability that affects the Enterprise edition on Windows systems. A remote attacker can exploit this vulnerability by tricking a user into viewing a specially crafted HTML page, potentially exposing sensitive user information. This could lead to data theft or account compromise depending on what information is leaked.

Technical details

This is an information leak vulnerability (CWE-200/203) in Google Chrome's Enterprise variant on Windows prior to version 153.0.8010.36. The vulnerability is triggered via a malicious HTML page sent over the network, requiring user interaction (visiting the page). The attack is unauthenticated and does not require elevated privileges. An attacker can craft a specially designed HTML page that exploits this flaw to access sensitive data from the user's browser session or system. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Windows

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats