CVE-2026-87513
PoC massMissing Authorization in Google Chrome ControlledFrame Bypasses Access Restrictions
This is a missing-authorization flaw (CWE-862) in the ControlledFrame component of Google Chrome, rated Medium by Chromium. A remote attacker triggers it by using social engineering to convince a user to open a crafted HTML page, so exploitation requires user interaction. Successful exploitation allows the attacker to bypass system access restrictions, with a high integrity impact (unauthorized changes or actions) but no direct confidentiality or availability impact per the CVSS vector. Users running Google Chrome prior to version 153.0.8010.36 are affected. There is no confirmed in-the-wild exploitation so far: the flaw is not in CISA KEV, EPSS assigns a 0.3% 30-day exploitation probability, and one public proof-of-concept reference exists on the Chromium issue tracker.
What to do: Update Google Chrome to version 153.0.8010.36 or later (check the current version at chrome://settings/help and force an update if needed). Until updates are fully deployed, caution users against opening HTML pages from untrusted sources, since the attack depends on social engineering. Track the referenced Chromium issue (511773417) for any escalation from proof-of-concept to in-the-wild exploitation.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.