• PATCH AVAILABLE

CVE-2026-87544: authorization bypass in Google Chrome

A remote attacker can bypass authorization checks in Google Chrome Extensions to reach a privileged browser page, potentially exposing or modifying privileged functionality; this is tracked as CVE-2026-87544. The flaw affects Chrome 153 branch releases prior to 153.0.8010.36 and is exploitable via a crafted HTML page supplied by the attacker. The vendor has released a fix in 153.0.8010.36; exploitation requires delivering the crafted page to a target (the report describes use of a malicious HTML page).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00335
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Apply the vendor patch immediately: Google released 153.0.8010.36 to fix this authorization bypass. Treat as high priority because a browser update is available that directly remediates the issue.

What is CVE-2026-87544?

A remote attacker can bypass authorization checks in Google Chrome Extensions to reach a privileged browser page, potentially exposing or modifying privileged functionality; this is tracked as CVE-2026-87544. The flaw affects Chrome 153 branch releases prior to 153.0.8010.36 and is exploitable via a crafted HTML page supplied by the attacker. The vendor has released a fix in 153.0.8010.36; exploitation requires delivering the crafted page to a target (the report describes use of a malicious HTML page).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
153.x153.0.8010.36 – before 153.0.8010.36153.0.8010.36

Is CVE-2026-87544 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-87544

  1. Update Chrome to 153.0.8010.36 or later
  2. Block or restrict access to untrusted web content and limit exposure to attacker-controlled pages
  3. Follow vendor guidance and release notes for any additional mitigation steps
  4. Monitor browser telemetry and logs for unexpected access to privileged Extension pages

Frequently asked questions

Is CVE-2026-87544 being actively exploited?

There are no public reports of active exploitation of CVE-2026-87544 as of 2026-09-29.

Which Chrome versions are affected by CVE-2026-87544?

Chrome releases in the 153 branch prior to 153.0.8010.36 are affected; the issue is fixed in 153.0.8010.36.

Is there a patch for CVE-2026-87544?

Yes. Google fixed the vulnerability in Chrome version 153.0.8010.36; update to that version or later.

Does CVE-2026-87544 require authentication?

No prior authentication is described; the vulnerability allows a remote attacker to bypass system access restrictions via a crafted HTML page to reach a privileged Extensions page.

References