Junglewise Threat Intelligence

CVE-2026-87631: Google Chrome missing authorization in DOM

CVE-2026-87631 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a missing authorization flaw in its DOM handling that could allow an attacker to craft a malicious HTML page and trick users into viewing it, potentially exposing sensitive information. This affects millions of users and could lead to unauthorized access to private data displayed in web pages.

Technical details

A missing authorization vulnerability exists in the DOM component of Google Chrome prior to version 153.0.8010.36. The flaw allows a remote attacker to craft a malicious HTML page that bypasses authorization checks, enabling unauthorized access to sensitive information. The attack requires user interaction (visiting the crafted page) but no authentication is needed from the attacker. Exploitation results in potential information disclosure. The vulnerability was fixed in Chrome 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats