Junglewise Threat Intelligence

CVE-2026-87498: Google Chrome missing authorization in WebUI

CVE-2026-87498 · Severity: low · CVSS 3.1 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebUI component failed to properly validate user permissions, allowing an attacker with control over the browser's rendering process to bypass website origin restrictions. This could enable unauthorized access to sensitive web resources and cross-site data theft if an attacker can compromise the renderer through other means.

Technical details

This vulnerability is a missing authorization check in Chrome's WebUI component prior to version 153.0.8010.36. The root cause is insufficient validation of user permissions when accessing WebUI pages. The attack requires the renderer process to be compromised first (a critical precondition), after which an attacker can craft a malicious HTML page to bypass the same-origin policy. Successful exploitation allows unauthorized access to origin-restricted resources. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: patched: Chrome 153.0.8010.36 released
  • 2026-09-09: disclosed

References

Related threats