CVE-2026-87473
Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Scoring
- CVSS base score
- 1.5
- EPSS probability
- 0.27%
- CWE
- CWE-863
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-89151 — Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow...
- CVE-2026-78134 — strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins...
- CVE-2026-81905 — Concrete CMS below 9.5.3 does not enforce validation-hash type on redemption, allowing a hash issued for one purpose to be redeemed for another.
- CVE-2026-75624 — IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service
- CVE-2026-85025 — Langflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guards
- CVE-2026-87107 — Consul vulnerable to an authorization bypass in the catalog deregistration path
- CVE-2026-87090 — Consul vulnerable to an authorization bypass in the catalog node-write path
- CVE-2026-88044 — rclone: RC per-server auth-proxy bypass