CVE-2026-87447
PoC massIncorrect Authorization in Google Chrome Network Allows Origin Policy Bypass
CVE-2026-87447 is an incorrect authorization flaw (CWE-863) in the Network component of Google Chrome that lets the browser's web origin policy — the isolation boundary between websites — be bypassed. A remote attacker triggers it by using social engineering to convince a user to install or interact with a crafted Chrome extension, which then exploits the flawed authorization checks. The attacker gains the ability to circumvent origin-based isolation, which the CVSS scoring characterizes as an integrity impact (C:N/I:H/A:N — no confidentiality or availability loss is scored). All Google Chrome users running versions prior to 153.0.8010.36 are affected; Google rated the flaw High under the Chromium security severity scheme. There is no confirmed in-the-wild exploitation so far: the issue is not on CISA KEV, EPSS estimates only a 0.3% probability of exploitation within 30 days (21st percentile), and one public proof-of-concept reference exists on the Chromium issue tracker.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify via chrome://settings/help (or chrome://version), relaunching the browser so the auto-update takes effect. Until patched, enterprises can reduce risk by restricting extension installation via allowlist/blocklist policies, since exploitation depends on social engineering plus a crafted extension. Track the linked Chromium issue (issues.chromium.org/issues/503464711) for updates; the flaw is not currently on CISA KEV.
| google chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.