CVE-2026-87584
PoC massIncorrect Authorization in Google Chrome WebUI Bypasses Privileged Page Access
CVE-2026-87584 is an incorrect authorization flaw (CWE-863) in the WebUI component of Google Chrome. A remote attacker can trigger it by luring a user into opening a crafted HTML page, which then allows bypassing system access restrictions to reach a privileged page in the browser. The attacker gains unauthorized access to privileged WebUI functionality, with high integrity impact per the CVSS vector (6.5, confidentiality and availability unaffected). All users running Google Chrome prior to 153.0.8010.36 are affected. No in-the-wild exploitation is confirmed: the flaw is absent from CISA's KEV catalog, EPSS assigns only a 0.2% 30-day exploitation probability, and the sole public reference is a Chromium issue-tracker entry.
What to do: Upgrade Google Chrome to version 153.0.8010.36 or later and enforce the update centrally via enterprise browser management policies; no workaround beyond updating has been published. Until patched, exercise caution with untrusted links and HTML pages, and verify managed fleets contain no browsers on versions before 153.0.8010.36.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.