CVE-2026-87441
PoC massMissing Authorization in Chrome Downloads Enables Access-Restriction Bypass via Extension
CVE-2026-87441 is a missing-authorization flaw (CWE-862) in the Downloads component of Google Chrome, fixed in Chrome 153.0.8010.36. It is triggered when a crafted Chrome extension interacts with the Downloads subsystem in a way that skips the intended authorization check, and the CVSS vector (UI:R) indicates user interaction, such as running the malicious extension, is required. An attacker who exploits it can bypass system access restrictions related to downloads, with integrity impact only (C:N/I:H/A:N per the CVSS score of 6.5, Medium). All users running affected Chrome versions prior to 153.0.8010.36 are in scope, with vendor CPE data listing Google Chrome as the sole affected product. Exploitation has not been confirmed in the wild: the flaw is not in CISA KEV, EPSS estimates only a 0.3% probability of exploitation within 30 days, and one public proof-of-concept reference exists in the Chromium issue tracker.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version via chrome://version; enterprises should push the update through patch management and audit installed extensions. No workaround is documented, but reviewing installed extensions and blocking untrusted ones reduces exposure until patching completes.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.