ZeroHour

CVE-2026-87475

PoC mass

Missing Authorization in Google Chrome Omnibox Enables Privileged Page Access

CVSS 3.1
6.5 medium
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-87475 is a missing-authorization flaw (CWE-862) in the Omnibox (address bar) of Google Chrome, rated Medium severity by Google with a CVSS 3.1 base score of 6.5. A remote attacker must use social engineering to persuade a user to interact with a crafted HTML page, after which the attacker can bypass system access restrictions and gain access to a privileged page. Per the CVSS scoring, there is no impact on confidentiality or availability, but a high impact on integrity, meaning the attacker can act on or manipulate the state of a privileged page. All Google Chrome users running versions prior to 153.0.8010.36 are affected. There are no confirmed reports of exploitation in the wild (not in CISA KEV; EPSS 30-day exploitation probability is 0.2%), but one public proof-of-concept reference exists in the Chromium issue tracker.

What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as it is available through Chrome's auto-update channel. Because exploitation requires user interaction, reinforce user awareness about unsolicited links and crafted pages until fleets are patched, and have administrators push and verify the fixed version via endpoint management tooling. Organizations relying on Chromium-based derivatives should track and apply the equivalent fix from their downstream vendor.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global installed base, effectively all unpatched users until updated) — Chrome is the world's most widely deployed browser with a global user base in the billions, and every installation on a pre-153.0.8010.36 build is affected until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.