Junglewise Threat Intelligence

CVE-2026-87645: Google Chrome improper state validation in SafeBrowsing

CVE-2026-87645 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's SafeBrowsing feature, which protects users from malicious websites, contains a vulnerability in how it validates application state. A remote attacker could exploit this flaw by serving a specially crafted HTML page to bypass security restrictions on system access, potentially allowing unauthorized access to protected resources.

Technical details

This vulnerability is an improper state validation issue in the SafeBrowsing component of Chromium. The vulnerability allows a remote attacker to craft a malicious HTML page that, when loaded in affected versions of Chrome, can bypass system access restrictions. No special authentication or preconditions are required—an attacker simply needs to trick a user into visiting a malicious website. The vulnerability was patched in Chrome version 153.0.8010.36 and later. The root cause involves insufficient validation of state transitions in the SafeBrowsing security logic.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats