Description
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect authorization condition in the Loader component of Google Chrome that allows a malicious HTML page to be specially crafted so that a remote attacker can gain system access privileges. The flaw is classified as CWE‑863, which is an authorization Bypass. It does not directly expose code execution but enables the attacker to perform privileged operations normally blocked by the operating system through the browser’s privileged context.

Affected Systems

All operating systems that install Google Chrome before version 153.0.8010.36 are affected, regardless of platform, as the Loader component has been present across Chrome releases. The issue exists in every build of Chrome that predates the 153.0.8010.36 release.

Risk and Exploitability

While the Chromium security severity is listed as Low, the exploitation path requires social engineering to get a user to load a crafted HTML page. No EPSS score is available and the vulnerability is not represented in the CISA KEV catalog, suggesting that large‑scale exploitation is not currently documented. However, because the flaw allows a bypass of system access restrictions, it remains a concern for environments that allow untrusted web content or rely on Chrome for system administration tasks. The attack vector is inferred to be a crafted web page that the user would need to visit or otherwise trigger through a phishing or malicious link. The lack of public exploits and the social‑engineering requirement moderate the immediate risk to systems that enforce strict web filtering or user training.

Generated by OpenCVE AI on September 9, 2026 at 06:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later to obtain the authorization fix.
  • Implement web content filtering and phishing protection to reduce the likelihood that users encounter crafted malicious pages.
  • Enable or enforce Chrome's safe browsing features and consider disabling the Loader component if available through enterprise management settings.

Generated by OpenCVE AI on September 9, 2026 at 06:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Loader Authorization Bypass Enables System Access Escalation in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-863
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T00:10:05.875Z

Reserved: 2026-09-08T22:41:08.335Z

Link: CVE-2026-87575

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T01:17:15.277

Modified: 2026-09-09T01:17:15.277

Link: CVE-2026-87575

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T06:15:05Z

Weaknesses