Junglewise Threat Intelligence

CVE-2026-87610: Google Chrome incorrect authorization in Omnibox

CVE-2026-87610 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Omnibox (address bar and search component) contains an authorization flaw that allows remote attackers to bypass security controls and gain access to privileged browser pages. An attacker can craft a malicious HTML page that, when visited, escalates access to restricted functionality, potentially compromising browser security and user data.

Technical details

The vulnerability is an incorrect authorization flaw in the Omnibox component of Google Chrome versions prior to 153.0.8010.36. The root cause is insufficient access control validation that allows a remote attacker to bypass system access restrictions through a crafted HTML page. No user interaction beyond visiting the malicious page is required. An attacker can leverage this to access privileged pages normally protected by browser security policies. The vulnerability has been patched in Chrome 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats