Junglewise Threat Intelligence

CVE-2026-87644: Google Chrome incorrect authorization in Views on Windows

CVE-2026-87644 · Severity: high · CVSS 8.3 · Published 2026-09-09

Executive brief

Google Chrome on Windows contains an authorization flaw in its Views component that could allow an attacker who has already compromised the browser's renderer process to bypass security restrictions and execute code outside the sandbox through social engineering. This could lead to complete compromise of user data and system security.

Technical details

This vulnerability is an incorrect authorization flaw in the Views component of Google Chrome on Windows. The attack requires an attacker to have already compromised the renderer process and to leverage social engineering to trick a user into interacting with a crafted HTML page. The vulnerability allows the attacker to potentially execute arbitrary code outside the sandbox, breaking the browser's fundamental security isolation. The flaw affects Chrome versions prior to 153.0.8010.36, and has been patched in version 153.0.8010.36 and later. The Chromium security team classified this as Medium severity, though it carries high practical impact due to sandbox escape potential.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36

References

Related threats