CVE-2026-87575
Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
- Affected products
- Google Chrome, Chromium
- Google Chrome
- < 153.0.8010.36
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.1% (4th percentile)
- Weakness
- CWE-863
- NVD status
- Analyzed
- Published
- 2026-09-09
CVE-2026-87575 at NVD
1 known exploit for CVE-2026-87575
Proof-of-concept code and exploit modules indexed by Sploitus