Junglewise Threat Intelligence

CVE-2026-87490: Google Chrome information leak in Transactions Platform

CVE-2026-87490 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an information leak vulnerability in its Transactions Platform component that allows attackers to extract sensitive information through a specially crafted HTML page. This could expose user data or transaction details to unauthorized parties, impacting customer trust and potentially violating data protection regulations.

Technical details

This is an information disclosure vulnerability in Chrome's Transactions Platform component. The vulnerability can be exploited via a crafted HTML page delivered to a user, requiring no authentication or special privileges. An attacker can leverage this to obtain sensitive information from the affected system. The vulnerability was addressed in Chrome version 153.0.8010.36 and later. The Chromium project assessed this as low severity internally, though it has been assigned a CVSS score of 6.5 reflecting medium impact.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats