CVE-2026-87431

Google · Chrome

A missing authorization vulnerability in Google Chrome Extensions allows a remote, unauthenticated attacker to access sensitive information via a specially crafted extension.

Executive summary

Google Chrome contains a high-severity security flaw due to missing authorization in its extension architecture that enables remote information disclosure.

Vulnerability

This vulnerability, categorized as CWE-862 (Missing Authorization), occurs within the Chrome Extensions component. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that the flaw is exploitable by an unauthenticated remote attacker without requiring user interaction.

Business impact

The ability for an unauthenticated attacker to remotely exfiltrate sensitive data presents a significant risk to user privacy and organizational confidentiality. Although the CVSS score is 7.5, which falls in the High range, the potential for unauthorized data access could lead to severe regulatory non-compliance and loss of intellectual property if leveraged against high-value targets.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later to apply the necessary authorization checks.

Proactive Monitoring: Review browser extension deployment policies and monitor for unusual network activity originating from browser-based processes that might indicate data exfiltration.

Compensating Controls: Implement organizational policies that restrict the installation of third-party extensions via Group Policy or MDM solutions until systems are patched.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the remote, unauthenticated nature of this vulnerability, immediate patching is required to prevent potential information disclosure. Administrators should prioritize the deployment of the Chrome update across the enterprise to ensure that the extension authorization mechanism is correctly enforced.

More Google CVEs all →

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources