Description
Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to system resources via crafted web content when using Chrome
Action: Patch
AI Analysis

Impact

The vulnerability resides in the ControlledFrame component of Google Chrome, where an authorization check is missing. When a user visits a specially crafted HTML page, the browser can bypass the operating system’s access controls. This gives an attacker the ability to read or execute files outside the sandbox, compromising confidentiality and integrity of the system. The weakness is identified as CWE‑862, Missing Authorization, and the advisory rates the issue as Medium severity.

Affected Systems

Google Chrome browsers prior to build 153.0.8010.36, installed on any operating system that supports this version of Chrome. The affected builds are part of the stable channel for desktop. In effect, any user running a Chrome version older than 153.0.8010.36 is vulnerable.

Risk and Exploitability

The vulnerability can be exploited through a remote attack vector. An attacker needs to entice a user to load a malicious web page, which can be done via social engineering or compromised websites. Once the page loads, the browser’s missing authorization allows bypassing of system access restrictions, exposing sensitive files or data. The CVSS base score is 6.5, the EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits as of this analysis. Nevertheless, the attack requires only a simple crafted page and social engineering, making it relatively easy to attempt.

Generated by OpenCVE AI on September 10, 2026 at 23:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later
  • If an upgrade cannot be performed immediately, configure Chrome policies to disable or restrict controlled frames, such as blocking access to untrusted origins
  • Implement user awareness training to recognize phishing and social engineering attempts that could deliver malicious HTML pages

Generated by OpenCVE AI on September 10, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Fri, 11 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Missing Authorization in ControlledFrame Allows Arbitrary Webpage to Bypass System Access Restrictions

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Missing Authorization in ControlledFrame Allows Arbitrary Webpage to Bypass System Access Restrictions

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in ControlledFrame in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T18:20:47.507Z

Reserved: 2026-09-08T22:39:12.422Z

Link: CVE-2026-87513

cve-icon Vulnrichment

Updated: 2026-09-10T18:20:31.831Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:08.370

Modified: 2026-09-10T20:49:19.870

Link: CVE-2026-87513

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:14Z

Weaknesses