CVE-2026-87475: Google Google Chrome vulnerability
Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to induce a user to interact with a crafted HTML page; the issue is described as requiring social engineering. The attack is remote and does not require the attacker to be local to the affected system.
Which Chrome versions should be remediated?
Google Chrome versions prior to 153.0.8010.36 are affected according to the available information. Update affected desktop Chrome installations to 153.0.8010.36 or later.