ZeroHour

CVE-2026-87441

PoC mass

Missing Authorization in Chrome Downloads Enables Access-Restriction Bypass via Extension

CVSS 3.1
6.5 medium
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-87441 is a missing-authorization flaw (CWE-862) in the Downloads component of Google Chrome, fixed in Chrome 153.0.8010.36. It is triggered when a crafted Chrome extension interacts with the Downloads subsystem in a way that skips the intended authorization check, and the CVSS vector (UI:R) indicates user interaction, such as running the malicious extension, is required. An attacker who exploits it can bypass system access restrictions related to downloads, with integrity impact only (C:N/I:H/A:N per the CVSS score of 6.5, Medium). All users running affected Chrome versions prior to 153.0.8010.36 are in scope, with vendor CPE data listing Google Chrome as the sole affected product. Exploitation has not been confirmed in the wild: the flaw is not in CISA KEV, EPSS estimates only a 0.3% probability of exploitation within 30 days, and one public proof-of-concept reference exists in the Chromium issue tracker.

What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version via chrome://version; enterprises should push the update through patch management and audit installed extensions. No workaround is documented, but reviewing installed extensions and blocking untrusted ones reduces exposure until patching completes.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of Chrome installs (Chrome's global user base exceeds 3 billion), though auto-update means the currently unpatched population is much smaller — Chrome holds the largest browser market share (~65%) with a publicly estimated user base in the billions, so the potential affected install base is mass-scale even though Chrome's silent auto-update rapidly moves users past the vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.