CVE-2026-87492
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- CWE
- CWE-863
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-46460 — Dell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and...
- CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
- CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
- CVE-2026-86755 — Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
- CVE-2026-86754 — Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
- CVE-2026-86753 — snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
- CVE-2026-86752 — snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
- CVE-2026-86750 — snipe-it before 8.7.0 Authorization Bypass via API User Create/Update