Junglewise Threat Intelligence

CVE-2026-87593: Google Chrome information leak in Editing

CVE-2026-87593 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains an information disclosure vulnerability in its Editing component that allows remote attackers to access sensitive information by tricking users into visiting a malicious web page. This could expose confidential data, browsing history, or cached content to unauthorized parties without requiring any special user permissions beyond visiting a compromised website.

Technical details

This is an information leak vulnerability in Google Chrome's Editing component, reachable via a crafted HTML page delivered over the network. The vulnerability allows a remote attacker to obtain sensitive information without prior authentication. The flaw was present in Chrome versions prior to 153.0.8010.36 and has been patched in that release. The attack vector requires only that a user visit a malicious website, making this a high-impact but relatively easy-to-exploit issue.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats