Description
Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A missing authorization check in the Omnibox component of Google Chrome allows a remote attacker who successfully social‑engineers a victim to bypass system access restrictions. By manipulating a crafted HTML page entered into the Omnibox, the attacker can trigger the browser to load a privileged page that the victim would normally be barred from visiting. This flaw, identified as CWE‑862, effectively grants the attacker elevated local privileges on the affected machine. The flaw is also mapped to CWE‑551, indicating unauthorized access to privileged resources.

Affected Systems

Google Chrome browsers prior to version 153.0.8010.36 are vulnerable. The fix is available in the stable channel update released on September 8, 2026.

Risk and Exploitability

Chromium classifies the vulnerability as Medium severity. Its CVSS score is 6.5. Exploitation requires victim interaction with a crafted page; a social‑engineering approach is needed. The EPSS score is < 1%, and the flaw is not listed in the CISA KEV catalog, indicating no publicly known widespread exploitation. The risk remains moderate, with impact limited to devices running the affected Chrome version and depending on user behavior.

Generated by OpenCVE AI on September 10, 2026 at 23:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or newer.
  • Ensure Chrome auto‑update is enabled so the patch is applied automatically on all systems.
  • Educate users to avoid entering unknown URLs or clicking on suspicious content entered via the Omnibox to mitigate social‑engineering attempts.

Generated by OpenCVE AI on September 10, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Omnibox Authorization Bypass Allowing Privileged Page Access in Chrome chromium-browser: chromium-browser: Missing authorization in Omnibox
Weaknesses CWE-551
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Omnibox Authorization Bypass Allowing Privileged Page Access in Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T18:29:03.478Z

Reserved: 2026-09-08T22:38:08.448Z

Link: CVE-2026-87475

cve-icon Vulnrichment

Updated: 2026-09-10T18:28:40.895Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:04.090

Modified: 2026-09-10T20:51:56.437

Link: CVE-2026-87475

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:46Z

Links: CVE-2026-87475 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses
  • CWE-551

    Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

  • CWE-862

    Missing Authorization