CVE-2026-87469
Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via crafted network traffic. (Chromium security severity: Low)
Scoring
- CVSS base score
- 1.5
- CWE
- CWE-20
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2025-7062 — Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
- CVE-2026-12855 — H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code execution.
- CVE-2026-87083 — tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
- CVE-2026-87568 — Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87510 — Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87600 — Improper input validation in Safebrowsing in Google Chrome on on Android prior to 153.0.8010.36...
- CVE-2026-87472 — Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87599 — Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote...