Junglewise Threat Intelligence

CVE-2026-87548: Google Chrome improper state validation in Installer

CVE-2026-87548 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's installer component contains improper state validation that could allow an attacker to bypass system access restrictions through a crafted HTML page. This could potentially enable unauthorized users to escalate privileges or circumvent security controls during the installation process.

Technical details

The vulnerability is an improper state validation flaw in Google Chrome's Installer component (Chromium severity: Medium). An attacker can craft a malicious HTML page that, when processed during the installation or update workflow, bypasses system access restrictions that are normally enforced. The attack requires user interaction (visiting a crafted page) and network access. A successful exploit allows an attacker to circumvent installer-level security controls. The fix is available in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats