CVE-2026-87569
massMissing Authorization in Google Chrome Views Allows Access Restriction Bypass
CVE-2026-87569 is a missing-authorization flaw (CWE-862) in the Views component of Google Chrome, rated High (Chromium security severity) and fixed in Chrome 153.0.8010.36. An attacker must first socially engineer a user into opening and interacting with a crafted HTML page; because the required authorization check is absent, the page can then bypass system access restrictions that Chrome would otherwise enforce. Per the CVSS 3.1 score of 8.8 (AV:N/AC:L/PR:N/UI:R), the impact spans high confidentiality, integrity, and availability within the affected context, but it requires no privileges and hinges on user interaction. All Google Chrome users running versions prior to 153.0.8010.36 are affected until their browser auto-updates. There is currently no known exploitation in the wild, no public proof-of-concept, and a low exploitation probability (EPSS 0.2%, percentile 7); the flaw is not in CISA's KEV catalog.
What to do: Update Google Chrome to 153.0.8010.36 or later and confirm the installed version at chrome://settings/help; administrators should enforce the update via browser update management policies. Because exploitation requires social engineering and user interaction, exercise caution with unsolicited links and interactive web pages until browsers are patched. No workarounds were specified in the advisory, so patching is the primary remediation.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Views in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.