Junglewise Threat Intelligence

CVE-2026-87476: Google Chrome incorrect authorization in Loader

CVE-2026-87476 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Loader component contains an authorization flaw that allows an attacker to craft a malicious HTML page to bypass security controls. An attacker can trick a user into visiting the page to extract sensitive information from the browser, potentially exposing personal or account data without requiring special privileges.

Technical details

This vulnerability is an incorrect authorization issue in Chrome's Loader component that allows bypass of access controls. An attacker can craft a specially designed HTML page to trigger the flaw; the attack is remote and requires user interaction (visiting the malicious page) but no authentication. The vulnerability allows an attacker to obtain sensitive information that should normally be protected. The vulnerability was patched in Chrome version 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel

References

Related threats