CVE-2026-87537
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- google/chrome
- Source
- chrome-cve-admin@google.com
References
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.htmlRelease Notes, Vendor Advisory
- https://issues.chromium.org/issues/498732709Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.