ZeroHour

CVE-2026-87431

mass

Missing Authorization in Google Chrome Extensions Enables Data Disclosure

CVSS 3.1
7.5 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-87431 is a missing-authorization flaw (CWE-862) in the extensions subsystem of Google Chrome, rated Medium by Chromium but scored 7.5 (High) under CVSS 3.1 because of its confidentiality impact. A remote attacker can trigger the issue with a crafted Chrome extension that bypasses authorization checks, allowing the attacker to obtain sensitive information; per the CVSS vector, no privileges, user interaction, or integrity/availability impact are involved. Users running Google Chrome versions prior to 153.0.8010.36 are affected. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only about a 0.3% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Update Chrome to 153.0.8010.36 or later and verify the running version at chrome://version, since the built-in auto-updater should deliver the fix. Review installed extensions for anything not intentionally added, and enterprises should enforce extension allowlists through Chrome management policies. With no public PoC or known exploitation, this can be addressed in the normal update cycle but should not be deferred, as sensitive-data disclosure flaws are commonly weaponized once disclosed.

Affected
Google ChromeAll versions prior to 153.0.8010.36 (fixed in 153.0.8010.36)
Estimated exposure
mass≈3+ billion Chrome users (global browser install base), though Chrome's auto-update quickly shrinks the vulnerable pool — Chrome holds roughly two-thirds of global desktop browser market share with a multi-billion user install base, and the flaw sits in the core extensions subsystem, so any Chrome user on a pre-153.0.8010.36 build is plausibly exposed, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.