CVE-2026-87571: Google Google Chrome vulnerability
Published Sep 9, 2026
·Updated
Improper certificate validation in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)
Affected Software
1 affected component
Google Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:10 AM
Data Sourced
via MITRE·12:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attacker must deliver crafted network traffic and rely on social engineering. The issue could then be used to bypass the web origin policy.
2
Which Chrome versions are affected?
Google Chrome versions prior to 153.0.8010.36 are affected. Updating to version 153.0.8010.36 or later addresses the affected version range.