Junglewise Threat Intelligence

CVE-2026-87629: Google Chrome incorrect authorization in Sources

CVE-2026-87629 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's developer tools Sources panel contains an authorization flaw that allows attackers to leak sensitive information. An attacker can craft a malicious web page and trick a user into visiting it, potentially exposing source code, API keys, or other confidential data visible in the development environment.

Technical details

This vulnerability is an incorrect authorization flaw in Chrome's Sources panel (developer tools). The vulnerability allows a remote attacker to leak sensitive information by crafting a malicious HTML page and leveraging social engineering to convince a user to visit it. The attack requires user interaction (convincing a user to open a crafted page), but does not require authentication. An attacker can exploit this to extract source code, credentials, or other sensitive data from the developer environment. The vulnerability is fixed in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats