Junglewise Threat Intelligence

CVE-2026-87571: Google Chrome improper certificate validation in Loader

CVE-2026-87571 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Loader component failed to properly validate SSL/TLS certificates, allowing an attacker to use social engineering and crafted network traffic to bypass web origin policy protections. This could enable attackers to trick users into visiting malicious sites that appear legitimate, potentially leading to credential theft, malware installation, or data compromise.

Technical details

This vulnerability involves improper certificate validation in Chrome's Loader component, a critical part of the browser's security model for enforcing web origin policy. An attacker can exploit this via crafted network traffic combined with social engineering tactics, without requiring any special privileges or user interaction beyond normal browsing. The vulnerability allows bypassing the same-origin policy and web origin enforcement, which could be chained with other attacks to compromise user security. Google fixed this issue in Chrome 153.0.8010.36 and later. The Chromium project classified this as Low severity, though the CVSS score of 5.4 reflects medium impact.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats