Description
Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This flaw occurs because Google Chrome versions prior to 153.0.8010.36 lack a critical authorization check. A malicious HTML page can cause the browser to treat content as if it had higher privileges, allowing the attacker to bypass access controls normally enforced by Chrome. The issue is mapped to CWE‑862, Missing Authorization Control, and is rated medium severity by Chromium. Based on the description, the attacker must deliver or embed a crafted page that the victim opens in Chrome to exploit the vulnerability.

Affected Systems

Any user running Google Chrome with a release earlier than 153.0.8010.36 on any supported desktop platform is vulnerable. No additional operating system or device restrictions are specified in the available data. The vulnerability affects the entire Chrome browsing session, not just individual tabs or extensions.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium impact. The EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is a crafted HTML page delivered over the network; the attacker only needs the victim to open the page in Chrome. Successful exploitation would elevate the attacker’s privileges within the Chrome process, potentially allowing actions that exceed the browser’s intended authorization scope. Based on the description, it is inferred that the victim must voluntarily navigate to or load the malicious page.

Generated by OpenCVE AI on September 9, 2026 at 23:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 153.0.8010.36 or later to apply the vendor‑provided fix.
  • Ensure Chrome automatic updates are enabled so that future patches reach affected systems promptly.
  • Implement browser‑security policies or a reputable web‑filtering solution to block access to untrusted or suspicious HTML content before it is opened in Chrome.

Generated by OpenCVE AI on September 9, 2026 at 23:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title Browser authorization bypass via crafted HTML page

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Browser authorization bypass via crafted HTML page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T18:15:07.921Z

Reserved: 2026-09-08T22:40:30.541Z

Link: CVE-2026-87556

cve-icon Vulnrichment

Updated: 2026-09-10T18:14:13.459Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:13.227

Modified: 2026-09-10T19:17:38.337

Link: CVE-2026-87556

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:15:17Z

Weaknesses