Junglewise Threat Intelligence

CVE-2026-87495: Google Chrome information leak in Scroll component

CVE-2026-87495 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a vulnerability in its Scroll component that allows an attacker with control over the renderer process to leak data across website boundaries using a specially crafted webpage. This could enable theft of sensitive information such as browsing data, cached credentials, or personal information from other websites a user is visiting.

Technical details

This is a cross-origin information leak vulnerability in Chrome's Scroll component affecting versions prior to 153.0.8010.36. The vulnerability requires an attacker to have already compromised the renderer process—typically through a separate vulnerability or exploit chain. Given the renderer process compromise requirement, the attack vector is local to the compromised process; however, the initial renderer compromise would likely be achieved via a malicious or compromised website (network vector). An attacker can leverage a crafted HTML page to exfiltrate data from other origins (cross-origin data leak). Google patched this in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats