Description
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Sensitive Data Access
Action: Apply Patch
AI Analysis

Impact

An incorrect authorization check in the Loader component of Google Chrome allows a remote attacker to inject a crafted HTML page that can read or exfiltrate sensitive data from the browser. The vulnerability resides in Chrome’s handling of certain document types and manifests as privileged access where only authorized pages should be permitted. Consequently, an attacker could potentially read user data or credentials that the browser holds, leading to privacy and compliance violations. This weakness is classified as CWE-863, indicating improper authorization that can be exploited without privileged user interaction, and it also represents a CWE-551 access control flaw.

Affected Systems

Google Chrome users running versions prior to 153.0.8010.36 are affected. All desktop installations of the Chrome browser from earlier releases are vulnerable until the update that resolves the authorization flaw is applied.

Risk and Exploitability

The CVSS score is 6.5, indicating medium severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is through a crafted HTML page delivered via a remote server or local file that the user is tricked into opening. While exploitation might not be trivial, the absence of mitigation in earlier versions means a successful attack would directly expose sensitive information to a remote adversary.

Generated by OpenCVE AI on September 9, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 153.0.8010.36 or later, which includes the authorization fix
  • Configure Chrome to enforce strict site isolation and disable unrestricted local file access when possible
  • Ensure automatic updates are enabled to receive security patches promptly

Generated by OpenCVE AI on September 9, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote Attacker May Gain Sensitive Data via Unauthorized HTML Loader chromium-browser: chromium-browser: Incorrect authorization in Loader
Weaknesses CWE-551
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Remote Attacker May Gain Sensitive Data via Unauthorized HTML Loader

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T14:37:37.047Z

Reserved: 2026-09-08T22:38:09.628Z

Link: CVE-2026-87476

cve-icon Vulnrichment

Updated: 2026-09-09T14:35:48.459Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:04.210

Modified: 2026-09-09T17:19:38.503

Link: CVE-2026-87476

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:45Z

Links: CVE-2026-87476 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T01:30:13Z

Weaknesses
  • CWE-551

    Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

  • CWE-863

    Incorrect Authorization