ZeroHour

CVE-2026-87544

mass

Incorrect Authorization in Google Chrome Extensions Allows Privileged Page Access

CVSS 3.1
9.8 critical
EPSS
<1%p6
Published
()
Modified
AI analysis

CVE-2026-87544 is an incorrect authorization flaw (CWE-863) in the Extensions component of Google Chrome in which access restrictions are not properly enforced. A remote attacker can trigger it by convincing a user to open a crafted HTML page, which then lets the attacker bypass system access restrictions and reach an otherwise privileged page. Impact is limited by the flaw's scope — Google's Chromium security team rates it Low severity, although the published CVSS 3.1 base score is 9.8 (critical). All users running Google Chrome versions prior to 153.0.8010.36 are affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.2%, so no exploitation has been observed.

What to do: Update Chrome to 153.0.8010.36 or later; Chrome normally auto-updates, so verify the running version at chrome://version and restart the browser if needed. Administrators should confirm managed fleets received the fixed version through their update-management tooling. Given no known exploitation and Chromium's Low severity rating, standard patch cadence is sufficient.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion Chrome users/installs worldwide (all builds before the 153.0.8010.36 fix) — Chrome holds roughly 65% of global browser usage share with Google reporting over 3 billion users, and this flaw affects every build prior to the fixed release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.