Description
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Access Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization condition in the Loader component of Google Chrome that allows a malicious HTML page to be specially crafted so that a remote attacker can gain system access privileges. The flaw is classified as CWE‑863, which is an authorization Bypass. It does not directly expose code execution but enables the attacker to perform privileged operations normally blocked by the operating system through the browser’s privileged context.

Affected Systems

All operating systems that install Google Chrome before version 153.0.8010.36 are affected, regardless of platform, as the Loader component has been present across Chrome releases. The issue exists in every build of Chrome that predates the 153.0.8010.36 release.

Risk and Exploitability

While the Chromium security severity is listed as Low, the CVSS score of 5.4 path requires social engineering to get a user to load a crafted HTML page. The EPSS score is <1%, indicating a very low probability of exploitation and the vulnerability is not represented in the CISA KEV catalog, suggesting that large‑scale exploitation is not currently documented. However, because the flaw allows a bypass of system access restrictions, it remains a concern for environments that allow untrusted web content or rely on Chrome for system administration tasks. The attack vector is inferred to be a crafted web page that the user would need to visit or otherwise trigger through a phishing or malicious link. The lack of public exploits and the social‑engineering requirement moderate the immediate risk to systems that enforce strict web filtering or user training.

Generated by OpenCVE AI on September 10, 2026 at 17:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • Enable Chrome's safe browsing features.
  • Disable the Loader component via enterprise management settings if available.
  • Implement web content filtering and user training to reduce potential exposure.

Generated by OpenCVE AI on September 10, 2026 at 17:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Loader Authorization Bypass Enables System Access Escalation in Google Chrome

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Loader Authorization Bypass Enables System Access Escalation in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-14T12:46:46.047Z

Reserved: 2026-09-08T22:41:08.335Z

Link: CVE-2026-87575

cve-icon Vulnrichment

Updated: 2026-09-14T12:46:39.898Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:15.277

Modified: 2026-09-14T13:18:59.007

Link: CVE-2026-87575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:45:17Z

Weaknesses