Junglewise Threat Intelligence

CVE-2026-87580: Google Chrome incorrect authorization in WebAppInstalls

CVE-2026-87580 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebAppInstalls feature had an authorization flaw that could be exploited by an attacker who had already compromised the browser's renderer process. By combining the vulnerability with social engineering, an attacker could bypass Chrome's site isolation security feature—a critical boundary that prevents malicious websites from accessing data from legitimate ones. This could lead to unauthorized access to sensitive information across different websites.

Technical details

This is an incorrect authorization vulnerability in Chrome's WebAppInstalls component. The vulnerability requires an attacker to have already compromised the renderer process (a sandboxed component of the browser), and then leverage social engineering to trick a user into interacting with a crafted HTML page. By exploiting this authorization flaw, an attacker can bypass site isolation, Chrome's core security boundary that prevents one site's renderer from accessing another site's data. Patches are available in Chrome 153.0.8010.36 and later. The attack vector is network-based and requires user interaction combined with prior renderer compromise.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats