Junglewise Threat Intelligence

CVE-2026-87557: Google Chrome missing authorization in LocalNetworkAccess

CVE-2026-87557 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a missing authorization check in the LocalNetworkAccess component that allows a remote attacker with a compromised renderer process to bypass system access restrictions. An attacker could exploit this by serving a malicious HTML page to gain unauthorized access to local network resources on a user's system.

Technical details

This is an authorization bypass vulnerability in Chrome's LocalNetworkAccess component affecting versions prior to 153.0.8010.36. The root cause is missing authorization checks that fail to properly validate access to local network resources. The attack requires a compromised renderer process (sandboxed web content execution environment), which an attacker could achieve through other browser vulnerabilities or social engineering. A successful exploit allows an attacker to bypass system access restrictions and access restricted local network resources. The vulnerability was patched in Chrome 153.0.8010.36, released September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats