CVE-2026-87569
Google · Chrome
A missing authorization flaw in Google Chrome allows remote attackers to bypass system access restrictions using social engineering and a crafted HTML page.
Executive summary
Google Chrome versions prior to 153.0.8010.36 are vulnerable to a high severity authorization bypass that can be exploited by remote attackers to compromise system integrity.
Vulnerability
The vulnerability exists due to missing authorization in the Views component of Google Chrome. A remote, unauthenticated attacker can leverage social engineering techniques to trick a user into interacting with a crafted HTML page, resulting in a bypass of system access restrictions.
Business impact
The exploitation of this vulnerability poses a significant risk to organizational endpoints, as it allows attackers to circumvent security controls and potentially gain unauthorized access to system resources. With a CVSS score of 8.8, this flaw is categorized as high severity, indicating that successful compromise could lead to significant data exposure or loss of system control. Failure to remediate this vulnerability may expose the organization to malicious software execution and unauthorized system operations.
Remediation
Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to incorporate the necessary authorization checks.
Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or suspicious redirects occurring after user interaction with external web content.
Compensating Controls: Deploy endpoint protection solutions that can identify and block malicious HTML content or attempts to exploit browser-based authorization flaws.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for total impact on affected systems, organizations should prioritize the deployment of the browser update across all enterprise workstations. Ensure that automated update mechanisms are functioning correctly to minimize the window of exposure. Continuous monitoring of browser-based threat vectors is strongly advised to detect any potential exploitation attempts targeting this vulnerability.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written