Junglewise Threat Intelligence

CVE-2026-87569: Google Chrome missing authorization in Views

CVE-2026-87569 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Views component failed to properly authorize user actions, allowing attackers to bypass system access restrictions through a crafted webpage. An attacker could exploit this via social engineering to trick users into visiting a malicious page, potentially gaining unauthorized access to sensitive system features or data.

Technical details

A missing authorization vulnerability exists in the Views component of Google Chrome prior to version 153.0.8010.36. The vulnerability allows a remote attacker to bypass system access restrictions by leveraging social engineering with a crafted HTML page. The attack requires user interaction (visiting a malicious webpage) but no authentication. An attacker can exploit this to gain unauthorized access to restricted functionality. The vulnerability was patched in Chrome 153.0.8010.36.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats