Junglewise Threat Intelligence

CVE-2026-87531: Google Chrome information leak in CORS

CVE-2026-87531 · Severity: low · CVSS 3.1 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contained a cross-origin data leak vulnerability in its Cross-Origin Resource Sharing (CORS) implementation. An attacker with access to a compromised renderer process could craft a malicious HTML page to extract sensitive data from other websites that the victim was visiting. This could result in unauthorized access to private user information across different web origins.

Technical details

The vulnerability is an information disclosure flaw in the CORS mechanism of Google Chrome versions prior to 153.0.8010.36. The root cause involves improper enforcement of cross-origin boundaries in the renderer process, allowing an attacker who has already compromised the renderer to bypass CORS protections. The attack requires the renderer process to be compromised and the victim to visit a crafted HTML page. A successful exploit results in cross-origin data exposure. The vulnerability is fixed in Chrome 153.0.8010.36 and later releases.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats