CVE-2026-87479
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.30%
- CWE
- CWE-807
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-82533 — DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing
- CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)
- CVE-2026-85602 — Grav Form Plugin before 9.1.20 reCAPTCHA v3 Authentication Bypass
- CVE-2026-63041 — Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
- CVE-2026-54730 — authentik: Authentication Flow Bypass via Unguarded challenge_valid() in AuthenticatorEndpointGDTCStage and GoogleChromeStageView
- CVE-2026-53789 — rsync < 3.5.0 Arbitrary File Deletion via Malicious File List
- CVE-2026-64934 — Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision
- CVE-2026-19579 — Snipe-IT Checkout Request Cancellation IDOR