DIRAS TAKE
Apply the vendor patch immediately: Google released 153.0.8010.36 to fix this authorization bypass. Treat as high priority because a browser update is available that directly remediates the issue.
What is CVE-2026-87544?
A remote attacker can bypass authorization checks in Google Chrome Extensions to reach a privileged browser page, potentially exposing or modifying privileged functionality; this is tracked as CVE-2026-87544. The flaw affects Chrome 153 branch releases prior to 153.0.8010.36 and is exploitable via a crafted HTML page supplied by the attacker. The vendor has released a fix in 153.0.8010.36; exploitation requires delivering the crafted page to a target (the report describes use of a malicious HTML page).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 153.x | 153.0.8010.36 – before 153.0.8010.36 | 153.0.8010.36 |
Is CVE-2026-87544 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-87544
- Update Chrome to 153.0.8010.36 or later
- Block or restrict access to untrusted web content and limit exposure to attacker-controlled pages
- Follow vendor guidance and release notes for any additional mitigation steps
- Monitor browser telemetry and logs for unexpected access to privileged Extension pages
Frequently asked questions
Is CVE-2026-87544 being actively exploited?
There are no public reports of active exploitation of CVE-2026-87544 as of 2026-09-29.
Which Chrome versions are affected by CVE-2026-87544?
Chrome releases in the 153 branch prior to 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.
Is there a patch for CVE-2026-87544?
Yes. Google fixed the vulnerability in Chrome version 153.0.8010.36; update to that version or later.
Does CVE-2026-87544 require authentication?
No prior authentication is described; the vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page to reach a privileged Extensions page.
References
- nvd.nist.gov/vuln/detail/CVE-2026-87544
- cve.org/CVERecord?id=CVE-2026-87544
- chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
- issues.chromium.org/issues/542355360
- All Google CVEs on CVE Radar
- CVEs published in September 2026