Description
Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Data Access via Unauthorized Extension
Action: Patch
AI Analysis

Impact

An incorrect authorization check in Chrome’s permission system for extensions allows a remote attacker, aided by social engineering, to install a crafted extension that can read sensitive information. The flaw resides in the way Chrome validates extension permissions, leading to a breach of confidentiality for data the user has authorized elsewhere. The vulnerability is classified as CWE‑863, reflecting an authorization failure due to improper checks.

Affected Systems

The issue affects all users of Google Chrome on the desktop platform running versions prior to 153.0.8010.36. Any user who has enabled or installed extensions on these affected versions is potentially at risk until the fix is applied.

Risk and Exploitability

The CVSS score of the vulnerability is 7.5, indicating medium severity according to Chromium. The EPSS score is <1%, and it is not currently listed in CISA’s KEV catalog, suggesting limited known exploitation. However, the exploitation path requires user interaction – the attacker must persuade a user to install a malicious extension. If social engineering succeeds, the attacker can read data that the user has authorized to extensions and exfiltrate it. Given the medium severity and requirement for social engineering, the overall risk is moderate but still important to mitigate promptly.

Generated by OpenCVE AI on September 10, 2026 at 15:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later.
  • Remove any installed extensions that were added to the system prior to the update, especially those from untrusted sources.
  • Implement Chrome Enterprise policies to restrict the installation of extensions to approved lists only.

Generated by OpenCVE AI on September 10, 2026 at 15:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension Authorization Bypass Enables Unauthorized Data Access
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Authorization Bypass Enables Unauthorized Data Access

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Permissions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T14:59:48.496Z

Reserved: 2026-09-08T22:23:08.564Z

Link: CVE-2026-87450

cve-icon Vulnrichment

Updated: 2026-09-10T14:59:08.642Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:01.340

Modified: 2026-09-10T16:18:04.897

Link: CVE-2026-87450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses