CVE-2026-87475
Missing authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-862
- Published
- 2026-09-09
- Last modified
- 2026-09-10
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-89054 — OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes
- CVE-2026-88959 — Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints
- CVE-2026-4129 — Improper Access Controls in NI SystemLink
- CVE-2026-88898 — AppFlowy-Cloud 0.7.2 through 0.9.64 Missing Workspace Authorization on Bulk Publish Endpoint
- CVE-2026-84821 — WordPress WP Fast Total Search plugin <= 1.82.284 - Broken Access Control vulnerability
- CVE-2026-81801 — WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability
- CVE-2026-81799 — WordPress Return Refund and Exchange For WooCommerce plugin <= 4.6.4 - Broken Access Control vulnerability
- CVE-2026-81794 — WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability