Description
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Web Origin Policy Bypass
Action: Immediate Patch
AI Analysis

Impact

An incorrect authorization in Chrome’s network stack allows a remote attacker to bypass the browser’s web origin policy, a high‑severity flaw that can expose cross‑origin data and potentially let a malicious user steal credentials or inject code. The vulnerability is classified as High severity by Chromium and can be exploited through a crafted Chrome extension rather than the normal web channel. It is a CWE‑863 authorization bypass vulnerability.

Affected Systems

Users running Google Chrome versions earlier than 153.0.8010. exists in the network layer and impacts any instance where a user might install a malicious extension trustable by social engineering.

Risk and Exploitability

The CVSS score of 6.5 defines this issue as medium severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation. The flaw is not currently listed in CISA’s KEV catalog. Although no public exploits are known, the vulnerability could be leveraged through social engineering to convince users to install a malicious extension. Once installed, the attacker can read or modify cross-origin data.

Generated by OpenCVE AI on September 11, 2026 at 02:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or newer to fix the authorization error.
  • Avoid installing extensions from untrusted or unknown sources; verify the authenticity and digital signatures of extensions before installation.
  • Configure Chrome enterprise policies or group policy to restrict or block extension installation in environments where the risk must be minimized.

Generated by OpenCVE AI on September 11, 2026 at 02:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Fri, 11 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Network Authorization Bypass via Extension

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Crafted Chrome Extension Bypasses Web Origin Policy

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Crafted Chrome Extension Bypasses Web Origin Policy

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T15:24:41.096Z

Reserved: 2026-09-08T22:23:02.694Z

Link: CVE-2026-87447

cve-icon Vulnrichment

Updated: 2026-09-10T15:24:38.253Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:01.007

Modified: 2026-09-10T19:17:47.923

Link: CVE-2026-87447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T03:30:16Z

Weaknesses