Description
Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-09
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: WebUI authorization bypass allowing origin policy escalation
Action: Assess Impact
AI Analysis

Impact

Chrome WebUI lacks proper authorization checks in versions prior to 153.0.8010.36, permitting a compromised renderer process to use a crafted HTML page to bypass the browser’s same‑origin policy. This flaw can let an attacker read or modify data belonging to other web origins, potentially exposing sensitive user information or executing arbitrary code within the browser sandbox.

Affected Systems

All Google Chrome releases older than 153.0.8010.36 are affected, including stable channel builds on desktop platforms. The vulnerability is specific to the Chrome WebUI and its renderer processes.

Risk and Exploitability

The flaw has a CVSS score of 3.1, indicating low severity. The EPSS score is <1%, suggesting a very low exploitation probability. It is not listed in the CISA KEV catalog. An attacker would need to compromise a renderer process and deliver a malicious HTML page, implying a remote exploitation scenario that requires prior foothold or social engineering. Given the low severity and very low exploitation probability, monitoring is appropriate but patching is still advisable.

Generated by OpenCVE AI on September 9, 2026 at 19:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later.
  • Disable or remove any Chrome internal flags or extensions that expose WebUI interfaces such as chrome://chromewebdata/ to untrusted contexts, using Chrome’s policy settings.
  • Configure the Chrome Enterprise policy to enforce strict same‑origin enforcement or to block WebUI access for non‑privileged users.

Generated by OpenCVE AI on September 9, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Missing authorization in WebUI
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

threat_severity

Important


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T17:11:00.453Z

Reserved: 2026-09-08T22:38:49.828Z

Link: CVE-2026-87498

cve-icon Vulnrichment

Updated: 2026-09-09T17:09:51.165Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:06.673

Modified: 2026-09-09T19:16:28.850

Link: CVE-2026-87498

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T00:09:36Z

Links: CVE-2026-87498 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:45:17Z

Weaknesses