Description
Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Published: 2026-09-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Google Chrome’s handling of certificate validation within the CORS mechanism allows a remote attacker to craft network traffic that deceives the browser into trusting a certificate that does not belong to the intended origin. This leads to a bypass of the web origin policy, granting the attacker the ability to access or manipulate data that should be confined to a trusted domain. The weakness is an instance of improper authentication or validation (CWE‑295).

Affected Systems

Google Chrome versions prior to 153.0.8010.36 are affected. All installations of Chrome that have not yet been updated to the referenced fixed release are vulnerable.

Risk and Exploitability

The vulnerability has a low intrinsic severity rating and is not listed in the CISA KEV catalog, indicating a comparatively small exploitation footprint at present. The EPSS score is not available, so the probability of exploitation remains uncertain. Likely exploitation requires a social‑engineering component, such as persuading a user to load a maliciously crafted website that communicates with a forged certificate. Once executed, the attacker could compromise confidentiality or integrity of cross‑origin resources but would not gain arbitrary system control. The overall risk is therefore considered moderate, pending further monitoring for signifiers of attack activity.

Generated by OpenCVE AI on September 9, 2026 at 05:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later where the certificate validation issue is resolved.
  • If an upgrade is not immediately feasible, apply network‑level filtering or a restrictive Content Security Policy on controlled sites to limit cross‑origin requests to trusted origins.
  • Conduct user awareness training to help staff recognize and avoid phishing or social‑engineering attempts that could lead to reliance on untrusted certificates.

Generated by OpenCVE AI on September 9, 2026 at 05:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in CORS Allows Web Origin Policy Bypass

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Weaknesses CWE-295
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T00:10:06.343Z

Reserved: 2026-09-08T22:40:24.115Z

Link: CVE-2026-87551

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T01:17:12.683

Modified: 2026-09-09T01:17:12.683

Link: CVE-2026-87551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T05:30:05Z

Weaknesses
  • CWE-295

    Improper Certificate Validation