Description
Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Origin Policy Bypass
Action: Update Chrome
AI Analysis

Impact

An incorrect authorization check in the Web Authentication system of Google Chrome versions prior to 153.0.8010.36 allows a remote attacker to bypass the browser's same‑origin policy by using a crafted Chrome extension. The flaw is a CWE‑863 condition where the browser fails to restrict authentication requests to the intended origin, giving the extension access to data from websites the user visits. If exploited, an attacker could read, modify, or inject credentials and other sensitive data across origin boundaries.

Affected Systems

Based on the description, the affected product is Google Chrome on the stable channel before version 153.0.8010.36. The issue is fixed in Chrome 153.0.8010.36 and later, so any user running an earlier stable release is vulnerable.

Risk and Exploitability

The Chromium severity of this flaw is Low; the CVSS score is 4.3 and the EPSS score is <1%. Attackers must deliver a malicious extension to the user, implying a social‑engineering or malicious‑web‑store vector. The flaw is not listed in CISA's KEV catalog and no public exploits have been documented, so widespread exploitation likelihood is low. Nonetheless, the capability to bypass origin restrictions could be leveraged by motivated actors.

Generated by OpenCVE AI on September 9, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or newer via the stable channel update.
  • If an immediate patch is not possible, configure Chrome to allow only extensions from trusted sources by setting the ExtensionInstallForcelist policy in the enterprise policy editor or Chrome Management console.
  • Audit and remove any unfamiliar or suspicious extensions from the browser.

Generated by OpenCVE AI on September 9, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Web Authentication Extension Authorization Bypass

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Chrome Web Authentication Extension Authorization Bypass

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T19:06:38.549Z

Reserved: 2026-09-08T22:40:42.114Z

Link: CVE-2026-87561

cve-icon Vulnrichment

Updated: 2026-09-10T18:35:33.770Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:13.763

Modified: 2026-09-10T20:17:30.277

Link: CVE-2026-87561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:00:10Z

Weaknesses