ZeroHour

CVE-2026-87629

PoC mass

Incorrect Authorization in Google Chrome Leaks Sensitive Information via Crafted Pages

CVSS 3.1
6.5 medium
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-87629 is an incorrect authorization flaw (CWE-863) in the Sources component of Google Chrome, rated Low severity by the Chromium security team. A remote attacker must use social engineering to convince a user to open a crafted HTML page, after which the browser's mishandled authorization checks allow sensitive information to be leaked. The impact is confidentiality-only: the attacker gains access to sensitive information but cannot execute code, modify data, or crash the browser, and no privileges are required beyond the user's click. Every user running Google Chrome prior to 153.0.8010.36 is affected until they update. Exploitation has not been confirmed in the wild: the flaw is not in CISA's KEV, EPSS assigns only a 0.2% 30-day exploitation probability (14th percentile), and there is a single public reference in the Chromium issue tracker.

What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version in the browser's About/Help settings, keeping automatic updates enabled. Because exploitation requires user interaction, remind users to avoid opening HTML pages or links from untrusted sources. Given the Low severity, 0.2% EPSS, and absence from CISA KEV, this can be handled in the normal patch cycle rather than as an emergency.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users/installations (Chrome's estimated global user base; all builds before 153.0.8010.36 until patched) — Chrome is the world's most widely used desktop and mobile browser with a publicly estimated user base in the billions, and any installation running a build older than 153.0.8010.36 remains exposed until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.