Junglewise Threat Intelligence

CVE-2026-87632: Google Chrome cross-site scripting in SanitizerAPI

CVE-2026-87632 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a cross-site scripting (XSS) vulnerability in its SanitizerAPI component that allows attackers to bypass the web origin policy. An attacker can craft a malicious HTML page that, when visited by a user, executes arbitrary code in the context of any website, potentially leading to unauthorized access to sensitive data, session hijacking, or malware distribution.

Technical details

A cross-site scripting vulnerability exists in Chrome's SanitizerAPI prior to version 153.0.8010.36, where insufficient input sanitization allows injection of malicious scripts. The vulnerability can be exploited via a crafted HTML page delivered to a user over the network; no authentication or special privileges are required. An attacker can bypass the web origin policy and execute arbitrary JavaScript in the victim's browser context, potentially stealing cookies, session tokens, or performing actions on behalf of the user. The vulnerability is fixed in Chrome 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats