Junglewise Threat Intelligence

CVE-2026-87656: Google Chrome improper state validation in Safe Browsing

CVE-2026-87656 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Executive brief

Google Chrome's Safe Browsing feature, which protects users from malicious websites, contained a flaw in how it validated security states. An attacker could exploit this vulnerability by crafting a malicious HTML page that bypasses system access restrictions, potentially allowing unauthorized access to protected resources or system features.

Technical details

The vulnerability is an improper state validation flaw in the Safe Browsing component of Google Chrome prior to version 153.0.8010.36. A remote attacker can craft a malicious HTML page to exploit this vulnerability and bypass system access restrictions. No authentication or special user interaction is required beyond the victim visiting a crafted web page. The attack vector is network-based. This vulnerability was assigned a low severity rating by the Chromium security team and has been patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats