Junglewise Threat Intelligence

CVE-2026-87550: Google Chrome improper CSS output encoding

CVE-2026-87550 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome before version 153.0.8010.36 contains a flaw in how it encodes or escapes CSS output, which could allow an attacker to bypass the browser's same-origin policy protections. An attacker could craft a malicious webpage that tricks the browser into allowing cross-origin access to sensitive user data or functionality, compromising the security isolation between websites.

Technical details

The vulnerability is an improper encoding or escaping issue in CSS output handling within Google Chrome. The flaw allows a remote attacker to bypass web origin policy (same-origin policy) through a crafted HTML page. The attack vector is network-based and requires user interaction (visiting a malicious webpage). An attacker can potentially access sensitive data or perform actions across origin boundaries. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats