Junglewise Threat Intelligence

CVE-2026-87508: Google Chrome incorrect authorization in Loader

CVE-2026-87508 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Loader component contained an authorization flaw that could allow an attacker to bypass web origin policy protections through a specially crafted web page. This could enable attackers to violate browser security boundaries and access resources from different web origins than intended, potentially leading to data theft or unauthorized actions on behalf of the user.

Technical details

An incorrect authorization vulnerability exists in the Loader component of Google Chrome prior to version 153.0.8010.36. The flaw allows a remote attacker to bypass the same-origin policy (web origin policy) via a crafted HTML page. The vulnerability is reachable through the network via a malicious webpage, requiring only that a user visit the page—no prior authentication or user interaction beyond page load is required. An attacker can exploit this to access cross-origin resources or conduct actions outside the intended origin boundaries. The vulnerability was patched in Chrome 153.0.8010.36 and later releases.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats