Junglewise Threat Intelligence

CVE-2026-87584: Google Chrome incorrect authorization in WebUI

CVE-2026-87584 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an authorization flaw in its web interface (WebUI) that allows attackers to bypass security restrictions and access privileged areas of the browser. An attacker can craft a malicious HTML page that, when visited by a user, exploits this vulnerability to gain unauthorized access to sensitive browser functionality that should be restricted.

Technical details

This is an incorrect authorization vulnerability in Chrome's WebUI component. The flaw allows a remote attacker to bypass system access restrictions to privileged pages through a crafted HTML page. The vulnerability is network-reachable and requires user interaction (visiting a malicious website). An attacker can gain unauthorized access to privileged browser functionality that should be protected from unprivileged content. The vulnerability has been fixed in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats