ZeroHour

CVE-2026-87569

mass

Missing Authorization in Google Chrome Views Allows Access Restriction Bypass

CVSS 3.1
8.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-87569 is a missing-authorization flaw (CWE-862) in the Views component of Google Chrome, rated High (Chromium security severity) and fixed in Chrome 153.0.8010.36. An attacker must first socially engineer a user into opening and interacting with a crafted HTML page; because the required authorization check is absent, the page can then bypass system access restrictions that Chrome would otherwise enforce. Per the CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:N/UI:R), the impact spans high confidentiality, integrity, and availability within the affected context, but it requires no privileges and hinges on user interaction. All Google Chrome users running versions prior to 153.0.8010.36 are affected until their browser auto-updates. There is currently no known exploitation in the wild, no public proof-of-concept, and a low exploitation probability (EPSS 0.2%, percentile 7); the flaw is not in CISA's KEV catalog.

What to do: Update Google Chrome to 153.0.8010.36 or later and confirm the installed version at chrome://settings/help; administrators should enforce the update via browser update management policies. Because exploitation requires social engineering and user interaction, exercise caution with unsolicited links and interactive web pages until browsers are patched. No workarounds were specified in the advisory, so patching is the primary remediation.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
mass≈3 billion Chrome users (Chrome is the world's dominant browser; every unpatched install below 153.0.8010.36 is exposed) — Chrome holds roughly 65% of global browser market share across desktop and mobile with an active install base on the order of billions of devices, and all installs remain exposed until the browser auto-updates to 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.