ZeroHour

CVE-2026-87450

mass

Incorrect Authorization in Google Chrome Permissions Exposes Sensitive Data

CVSS 3.1
7.5 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-87450 is an incorrect authorization flaw (CWE-863) in the permissions component of Google Chrome, where permission checks can be bypassed in certain extension scenarios. An attacker triggers it remotely by socially engineering a user into engaging with a crafted Chrome extension, and the flawed authorization then lets the extension reach data it should not access. The impact is confidentiality only: the attacker obtains sensitive information, with no code execution, privilege escalation, or system compromise implied. All Chrome users on versions prior to 153.0.8010.36 are affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.2%, so no active exploitation is currently known.

What to do: Update Chrome to version 153.0.8010.36 or later on all endpoints and verify the running build at chrome://version, since Chrome auto-update may already have delivered the fix. Administrators should confirm fleet versions via enterprise update management (MDM/GPO/Cloud policies) and review or restrict the installation of untrusted extensions as a precaution. Given Medium severity and no known exploitation, this is a routine patch-cycle priority rather than an emergency.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of Chrome installations (Chrome runs on an estimated 3+ billion devices worldwide; every build before 153.0.8010.36 is in scope) — Chrome's dominant global browser market share implies billions of users, and all builds prior to 153.0.8010.36 are affected until auto-update completes, though the flaw requires user exposure to a crafted extension to be exploited.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.