Junglewise Threat Intelligence

CVE-2026-87563: Google Chrome origin validation bypass in Paint

CVE-2026-87563 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Paint component contains an origin validation flaw that allows attackers to bypass cross-origin protections through a specially crafted HTML page. An attacker could exploit this to steal sensitive data from other websites that users have open in their browser, compromising user privacy and data security.

Technical details

This vulnerability is an origin validation error in Chrome's Paint component that fails to properly enforce cross-origin policies. An attacker can craft a malicious HTML page that, when opened in a victim's browser, bypasses the browser's same-origin policy to access data from other origins. The attack requires only that a user visit the attacker's crafted page while having other sensitive websites open in the same browser. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats