CVE-2026-87475
PoC massMissing Authorization in Google Chrome Omnibox Enables Privileged Page Access
CVE-2026-87475 is a missing-authorization flaw (CWE-862) in the Omnibox (address bar) of Google Chrome, rated Medium severity by Google with a CVSS 3.1 base score of 6.5. A remote attacker must use social engineering to persuade a user to interact with a crafted HTML page, after which the attacker can bypass system access restrictions and gain access to a privileged page. Per the CVSS scoring, there is no impact on confidentiality or availability, but a high impact on integrity, meaning the attacker can act on or manipulate the state of a privileged page. All Google Chrome users running versions prior to 153.0.8010.36 are affected. There are no confirmed reports of exploitation in the wild (not in CISA KEV; EPSS 30-day exploitation probability is 0.2%), but one public proof-of-concept reference exists in the Chromium issue tracker.
What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as it is available through Chrome's auto-update channel. Because exploitation requires user interaction, reinforce user awareness about unsolicited links and crafted pages until fleets are patched, and have administrators push and verify the fixed version via endpoint management tooling. Organizations relying on Chromium-based derivatives should track and apply the equivalent fix from their downstream vendor.
| Google Chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.