Description
Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Bypass Web Origin Policy
Action: Patch Immediately
AI Analysis

Impact

The flaw arises from incomplete cleanup in Google Chrome’s Browser before version 153.0.8010.36, allowing a remote attacker to craft a malicious extension that, once installed, bypasses the browser’s web origin policy. This access control weakness (CWE-459) could expose site‑specific data to malicious code and is rated Medium severity by Chromium.

Affected Systems

Google Chrome versions older than 153.0.8010.36 are affected. The issue was patched in the stable channel update released on 2026‑09‑08 and is documented in the Chromium issue tracker.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% reflects a very low probability of exploitation. Attackers would likely rely on social engineering to get a user to install a malicious extension that leverages the cleanup bug, potentially allowing read or modification of data from sites the user visits. The vulnerability is not listed in CISA’s KEV catalog, but success would compromise site‑specific confidentiality, integrity, or availability.

Generated by OpenCVE AI on September 10, 2026 at 23:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or newer
  • Avoid installing extensions from unknown or unverified developers
  • Disable installation of extensions from untrusted sources or restrict it via group policy

Generated by OpenCVE AI on September 10, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension Origin Policy Bypass via Crafted Extension

Thu, 10 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome Extension Origin Policy Bypass via Crafted Extension

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)
Weaknesses CWE-459
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T18:23:43.372Z

Reserved: 2026-09-08T22:22:35.193Z

Link: CVE-2026-87436

cve-icon Vulnrichment

Updated: 2026-09-10T18:23:18.878Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:16:59.793

Modified: 2026-09-10T19:26:00.943

Link: CVE-2026-87436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:00:15Z

Weaknesses