Junglewise Threat Intelligence

CVE-2026-87499: Google Chrome incorrect authorization in Network bypass

CVE-2026-87499 · Severity: high · CVSS 8.1 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an authorization vulnerability in its Network component that allows attackers with control over the browser's rendering process to bypass site isolation, a security mechanism that prevents cross-site data theft. Site isolation is a core protection in modern browsers that keeps websites' data separated even if malicious code runs in one site's tab. Exploitation of this flaw could allow an attacker to access sensitive data from other websites or steal authentication credentials.

Technical details

A flaw in Google Chrome's Network component allows incorrect authorization of cross-process requests, enabling bypass of site isolation. The vulnerability affects versions prior to 153.0.8010.36 and requires an attacker to have already compromised the browser's renderer process (through another vulnerability or user interaction). An attacker with renderer process control can craft a malicious HTML page that sends requests that bypass the site isolation boundaries, allowing access to data that should be protected. The vulnerability was fixed in Chrome 153.0.8010.36, which was released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats