Junglewise Threat Intelligence

CVE-2026-87561: Google Chrome Web Authentication authorization bypass

CVE-2026-87561 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Web Authentication system contained an authorization flaw that allowed a remote attacker to bypass web origin policy protections through a specially crafted Chrome extension. Web Authentication is a security mechanism that protects user credentials from phishing and unauthorized access. An exploit could allow an attacker to perform authentication operations on behalf of a user outside of legitimate security boundaries, potentially leading to unauthorized account access or credential theft.

Technical details

This vulnerability is an incorrect authorization flaw in Google Chrome's Web Authentication implementation, affecting versions prior to 153.0.8010.36. The vulnerability allows a remote attacker to bypass the web origin policy, a fundamental security control that restricts authentication operations to legitimate website origins. The attack requires a crafted Chrome extension to deliver the exploit. An attacker leveraging this flaw could trick users into installing a malicious extension, then use it to intercept or perform authentication operations that should be restricted to specific origins. Chrome 153.0.8010.36 and later versions contain the fix.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats