ZeroHour

CVE-2026-87513

PoC mass

Missing Authorization in Google Chrome ControlledFrame Bypasses Access Restrictions

CVSS 3.1
6.5 medium
EPSS
<1%p21
Published
()
Modified
AI analysis

This is a missing-authorization flaw (CWE-862) in the ControlledFrame component of Google Chrome, rated Medium by Chromium. A remote attacker triggers it by using social engineering to convince a user to open a crafted HTML page, so exploitation requires user interaction. Successful exploitation allows the attacker to bypass system access restrictions, with a high integrity impact (unauthorized changes or actions) but no direct confidentiality or availability impact per the CVSS vector. Users running Google Chrome prior to version 153.0.8010.36 are affected. There is no confirmed in-the-wild exploitation so far: the flaw is not in CISA KEV, EPSS assigns a 0.3% 30-day exploitation probability, and one public proof-of-concept reference exists on the Chromium issue tracker.

What to do: Update Google Chrome to version 153.0.8010.36 or later (check the current version at chrome://settings/help and force an update if needed). Until updates are fully deployed, caution users against opening HTML pages from untrusted sources, since the attack depends on social engineering. Track the referenced Chromium issue (511773417) for any escalation from proof-of-concept to in-the-wild exploitation.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
mass3+ billion Chrome users (Chrome's global installed base) — Chrome is reported to have roughly 3 billion users worldwide with about 65% browser market share, and the flaw sits in the browser's ControlledFrame component, so all installations running versions prior to 153.0.8010.36 are potentially in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.