Description
Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Actor component of Google Chrome, which permits an attacker to obtain sensitive information by viewing a crafted HTML page. The flaw is identified as CWE-862 and CWE-425, indicating insufficient authorization checks that allow unauthorized data access. Because the component deals with security-sensitive data, any memory or data exposed through this flaw could reveal private content to an adversary, undermining user confidentiality.

Affected Systems

Any installation of Google Chrome running a version earlier than 153.0.8010.36 is potentially vulnerable. Devices that have not applied the update containing the authorization fix are at risk of leaking sensitive data when browsing malicious or deceptively crafted web content.

Risk and Exploitability

The CVSS score of 6.5 marks the issue as medium severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The likely attack vector is a remote attacker delivering a malicious HTML page to the victim’s browser; based on the description, it is inferred that the attacker can entice the user to visit the crafted page, after which the missing authorization permits reading protected information. The vulnerability is not listed in CISA’s KEV catalog, but the medium severity combined with a remote attack surface suggests that timely remediation is recommended.

Generated by OpenCVE AI on September 9, 2026 at 14:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later. This update contains the authorization fix for the Actor component.
  • If an immediate upgrade is not feasible, restrict the execution of untrusted HTML content by enforcing policies that block dangerous JavaScript or disabling data access in the browser. This can reduce the risk until the patch is applied.
  • Monitor user activity for visits to unfamiliar or suspicious web pages and educate users about the risks of navigating to untrusted sites as a supplementary preventative measure.

Generated by OpenCVE AI on September 9, 2026 at 14:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome Enables Remote User Data Disclosure chromium-browser: chromium-browser: Missing authorization in Actor
Weaknesses CWE-425
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Missing Authorization in Chrome Enables Remote User Data Disclosure

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Actor in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T14:37:51.409Z

Reserved: 2026-09-08T22:22:50.101Z

Link: CVE-2026-87443

cve-icon Vulnrichment

Updated: 2026-09-09T14:35:50.597Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:00.570

Modified: 2026-09-09T16:37:35.260

Link: CVE-2026-87443

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:44Z

Links: CVE-2026-87443 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')

  • CWE-862

    Missing Authorization