CVE-2026-87629
PoC massIncorrect Authorization in Google Chrome Leaks Sensitive Information via Crafted Pages
CVE-2026-87629 is an incorrect authorization flaw (CWE-863) in the Sources component of Google Chrome, rated Low severity by the Chromium security team. A remote attacker must use social engineering to convince a user to open a crafted HTML page, after which the browser's mishandled authorization checks allow sensitive information to be leaked. The impact is confidentiality-only: the attacker gains access to sensitive information but cannot execute code, modify data, or crash the browser, and no privileges are required beyond the user's click. Every user running Google Chrome prior to 153.0.8010.36 is affected until they update. Exploitation has not been confirmed in the wild: the flaw is not in CISA's KEV, EPSS assigns only a 0.2% 30-day exploitation probability (14th percentile), and there is a single public reference in the Chromium issue tracker.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version in the browser's About/Help settings, keeping automatic updates enabled. Because exploitation requires user interaction, remind users to avoid opening HTML pages or links from untrusted sources. Given the Low severity, 0.2% EPSS, and absence from CISA KEV, this can be handled in the normal patch cycle rather than as an emergency.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Sources in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.