Junglewise Threat Intelligence

CVE-2026-87477: Google Chrome information leak in Core

CVE-2026-87477 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in its Core component that allows attackers to leak sensitive information through a crafted web page. An attacker can trick users into visiting a malicious webpage to steal private data without requiring any special user permissions or browser configuration changes.

Technical details

The vulnerability is an information disclosure issue in Chrome's Core component affecting versions prior to 153.0.8010.36. The flaw allows a remote attacker to leak sensitive information by crafting a malicious HTML page. The attack vector is network-based and requires the user to visit the attacker-controlled page. No authentication or elevated privileges are needed to exploit this vulnerability. The issue has been patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats