Junglewise Threat Intelligence

CVE-2026-87465: Google Chrome incorrect authorization in Downloads

CVE-2026-87465 · Severity: medium · CVSS 4.2 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's download feature contained an authorization flaw that allowed attackers who had compromised the browser's rendering process to spoof user interface elements through a malicious HTML page. This could mislead users into taking unintended actions or believing they are interacting with legitimate download prompts, potentially leading to further compromise or data exfiltration.

Technical details

The vulnerability is an incorrect authorization flaw in the Downloads component of Google Chrome. It requires a prior compromise of the renderer process, from which an attacker can craft a malicious HTML page to spoof UI elements and bypass authorization checks. The attack vector is network-based but requires renderer process compromise as a precondition. An attacker exploiting this can perform unauthorized actions that appear legitimate to the user. The vulnerability was fixed in Chrome version 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87465 publicly disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats