Junglewise Threat Intelligence

CVE-2026-87532: Google Chrome improper state validation in Safe Browsing

CVE-2026-87532 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Safe Browsing feature contained a flaw that allowed remote attackers to bypass system access protections through a crafted HTML page. An attacker could exploit this vulnerability to circumvent browser security controls designed to protect users from malicious content, potentially enabling unauthorized access to system resources.

Technical details

This vulnerability stems from improper state validation in Chrome's Safe Browsing component. The flaw allows a remote attacker to bypass system access restrictions by crafting a malicious HTML page. No authentication or user interaction beyond visiting a webpage is required. An attacker can achieve unauthorized system access by exploiting the validation bypass. The vulnerability was patched in Chrome version 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats