ZeroHour

CVE-2026-87584

PoC mass

Incorrect Authorization in Google Chrome WebUI Bypasses Privileged Page Access

CVSS 3.1
6.5 medium
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-87584 is an incorrect authorization flaw (CWE-863) in the WebUI component of Google Chrome. A remote attacker can trigger it by luring a user into opening a crafted HTML page, which then allows bypassing system access restrictions to reach a privileged page in the browser. The attacker gains unauthorized access to privileged WebUI functionality, with high integrity impact per the CVSS vector (6.5, confidentiality and availability unaffected). All users running Google Chrome prior to 153.0.8010.36 are affected. No in-the-wild exploitation is confirmed: the flaw is absent from CISA's KEV catalog, EPSS assigns only a 0.2% 30-day exploitation probability, and the sole public reference is a Chromium issue-tracker entry.

What to do: Upgrade Google Chrome to version 153.0.8010.36 or later and enforce the update centrally via enterprise browser management policies; no workaround beyond updating has been published. Until patched, exercise caution with untrusted links and HTML pages, and verify managed fleets contain no browsers on versions before 153.0.8010.36.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome holds roughly two-thirds global browser market share with an installed base of 3B+ users) — Chrome is the world's dominant desktop browser with an estimated 3+ billion users, and every user on a version before 153.0.8010.36 falls within the affected range.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.