CVE-2026-87431
massMissing Authorization in Google Chrome Extensions Enables Data Disclosure
CVE-2026-87431 is a missing-authorization flaw (CWE-862) in the extensions subsystem of Google Chrome, rated Medium by Chromium but scored 7.5 (High) under CVSS 3.1 because of its confidentiality impact. A remote attacker can trigger the issue with a crafted Chrome extension that bypasses authorization checks, allowing the attacker to obtain sensitive information; per the CVSS vector, no privileges, user interaction, or integrity/availability impact are involved. Users running Google Chrome versions prior to 153.0.8010.36 are affected. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only about a 0.3% probability of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Update Chrome to 153.0.8010.36 or later and verify the running version at chrome://version, since the built-in auto-updater should deliver the fix. Review installed extensions for anything not intentionally added, and enterprises should enforce extension allowlists through Chrome management policies. With no public PoC or known exploitation, this can be addressed in the normal update cycle but should not be deferred, as sensitive-data disclosure flaws are commonly weaponized once disclosed.
| Google Chrome | All versions prior to 153.0.8010.36 (fixed in 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.