Junglewise Threat Intelligence

CVE-2026-87551: Google Chrome improper certificate validation in CORS

CVE-2026-87551 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in how it validates digital certificates for cross-origin requests (CORS), which allows an attacker to bypass the browser's web origin policy through social engineering. An attacker could use crafted network traffic to trick users into exposing data or functionality they intended to keep isolated between different websites.

Technical details

The vulnerability is an improper certificate validation issue in Chrome's CORS (Cross-Origin Resource Sharing) implementation, classified as a low-severity flaw by Chromium. It allows a remote attacker to bypass the browser's same-origin policy through social engineering combined with crafted network traffic. The attack requires user interaction and does not directly enable arbitrary code execution or complete data theft, but can weaken the security boundary between different web origins. The vulnerability was fixed in Chrome version 153.0.8010.36 and later releases.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats