Junglewise Threat Intelligence

CVE-2026-87473: Google Chrome incorrect authorization in FileHandling

CVE-2026-87473 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's file handling system contains an authorization flaw that could allow a remote attacker to bypass system access restrictions through a crafted web page. An attacker leveraging social engineering to trick a user into visiting a malicious page could gain unauthorized access to files on the victim's system, potentially compromising sensitive data or system integrity.

Technical details

This vulnerability involves incorrect authorization checks in Chrome's FileHandling component. The flaw allows a remote attacker to bypass system access restrictions via a crafted HTML page, requiring user interaction (clicking a link or visiting a malicious site). The attack vector is network-based and relies on social engineering tactics. An attacker can exploit this to gain unauthorized access to restricted files or functionality. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats