Junglewise Threat Intelligence

CVE-2026-87591: Google Chrome extension authorization bypass

CVE-2026-87591 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in how it authorizes access to system functions when extensions are installed. An attacker could craft a malicious Chrome extension that bypasses security restrictions, potentially gaining unauthorized access to sensitive system resources or user data. This affects millions of Chrome users and could be exploited by distributing the malicious extension through official or unofficial channels.

Technical details

An incorrect authorization vulnerability exists in the Chrome extensions system prior to version 153.0.8010.36. The flaw allows a crafted Chrome extension to bypass system access restrictions through improper permission validation. Attack vector is network-based (extension delivery), though installation typically requires user interaction or social engineering. An attacker can create a malicious extension that gains elevated privileges beyond what legitimate extensions should access. The vulnerability was patched in Chrome 153.0.8010.36 released September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats