Junglewise Threat Intelligence

CVE-2026-87556: Google Chrome missing authorization in Browser

CVE-2026-87556 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's web browser contains a missing authorization control that allows a remote attacker to bypass system access restrictions through a malicious HTML page. This could enable attackers to access restricted functionality or data that should be protected by browser security policies, potentially compromising user privacy or system integrity without requiring any special user action beyond viewing a crafted webpage.

Technical details

This vulnerability is an authorization bypass in Chrome's Browser component, classified by Chromium as Medium severity. A remote attacker can craft a malicious HTML page that, when loaded by a victim, bypasses system access restrictions due to missing authorization checks. The attack requires no additional privileges or authentication from the attacker side, only that the victim visit or be redirected to the malicious page. Exploitation allows an attacker to access protected system resources or functionality that should be restricted. The vulnerability was patched in Chrome version 153.0.8010.36 (released September 8, 2026).

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36

References

Related threats