Junglewise Threat Intelligence

CVE-2026-87461: Google Chrome information leak in Core via crafted extension

CVE-2026-87461 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an information leak vulnerability in its Core component that allows attackers to steal cross-origin data through a malicious Chrome extension. This could enable attackers to access sensitive information from websites a user visits, including login credentials, personal data, or financial information. The vulnerability affects Chrome versions before 153.0.8010.36 and has been patched in the latest stable release.

Technical details

This is an information disclosure vulnerability in Chrome's Core component that permits cross-origin data leakage via a crafted Chrome extension. The vulnerability requires the attacker to distribute a malicious extension that users must install, making it a user-interaction vector. The flaw allows the extension to bypass cross-origin restrictions and read data from other websites, violating the browser's same-origin policy. The vulnerability has been resolved in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats