CVE-2026-87469: Input Validation
Published Sep 9, 2026
·Updated
Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)
Affected Software
1 affected component
Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:10 AM
Data Sourced
via MITRE·12:10 AM
DescriptionWeakness
Frequently Asked Questions
1
Which Chrome versions need to be updated?
Google Chrome versions prior to 153.0.8010.36 are affected. Update to 153.0.8010.36 or a later version.
2
What does an attacker need to exploit this issue?
The issue can be exploited remotely using crafted network traffic. The available information does not state that local access, user authentication, or installation of a malicious extension is required.
3
What is the potential impact of successful exploitation?
A successful attacker could bypass the web origin policy and reach a privileged page. The issue is in Chrome Extensions and is rated Low severity by Chromium.