CVE-2026-87450
massIncorrect Authorization in Google Chrome Permissions Exposes Sensitive Data
CVE-2026-87450 is an incorrect authorization flaw (CWE-863) in the permissions component of Google Chrome, where permission checks can be bypassed in certain extension scenarios. An attacker triggers it remotely by socially engineering a user into engaging with a crafted Chrome extension, and the flawed authorization then lets the extension reach data it should not access. The impact is confidentiality only: the attacker obtains sensitive information, with no code execution, privilege escalation, or system compromise implied. All Chrome users on versions prior to 153.0.8010.36 are affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.2%, so no active exploitation is currently known.
What to do: Update Chrome to version 153.0.8010.36 or later on all endpoints and verify the running build at chrome://version, since Chrome auto-update may already have delivered the fix. Administrators should confirm fleet versions via enterprise update management (MDM/GPO/Cloud policies) and review or restrict the installation of untrusted extensions as a precaution. Given Medium severity and no known exploitation, this is a routine patch-cycle priority rather than an emergency.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.