Junglewise Threat Intelligence

CVE-2026-87566: Google Chrome information disclosure in Layout rendering

CVE-2026-87566 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a timing-based information disclosure vulnerability in its page layout rendering engine that allows attackers to leak sensitive information by crafting malicious HTML pages. A remote attacker can exploit this flaw without user interaction beyond visiting a hostile website, potentially exposing sensitive data such as cookie values, tokens, or cross-site information.

Technical details

This vulnerability is an observable timing discrepancy in Chrome's Layout rendering component that can be exploited to infer sensitive information. The flaw allows remote attackers to craft HTML pages that expose subtle rendering differences or timing side-channels, enabling information leakage. The attack vector is network-based with no authentication or special user interaction required beyond viewing a malicious webpage. An attacker can use this to leak sensitive data such as authentication tokens, session identifiers, or cross-origin information. The vulnerability is patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats