Junglewise Threat Intelligence

CVE-2026-87521: Google Chrome information leak in WebMCP

CVE-2026-87521 · Severity: low · CVSS 3.1 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebMCP component contains an information leak vulnerability that could allow attackers to access cross-origin data if the browser's rendering engine has already been compromised. This affects users of Chrome versions before 153.0.8010.36, though the attack requires a pre-existing compromise of the renderer process. The issue is fixed in Chrome 153.0.8010.36 and later.

Technical details

This is an information disclosure vulnerability in WebMCP (Web Message Channel Protocol), a component handling cross-origin messaging in Chrome's renderer process. The vulnerability allows a remote attacker with an already-compromised renderer process to extract cross-origin data via a specially crafted HTML page, breaking the same-origin policy. Attack precondition: the renderer process must already be compromised through another vulnerability. The vulnerability affects Chrome versions prior to 153.0.8010.36, which includes the fix (reported in Chrome 153 stable release on 2026-09-08).

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats