CVE-2026-87509
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.15%
- CWE
- CWE-863
- Published
- 2026-09-09
- Last modified
- 2026-09-10
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-88894 — Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout
- CVE-2026-88884 — Renovate before 44.3.1 Authentication Bypass via Digest Updates
- CVE-2026-88862 — Capgo API Key Manager Authentication Bypass via x-limited-key-id
- CVE-2026-88860 — Capgo Authorization Bypass via Stale Channel Permission Overrides
- CVE-2026-87803 — An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed...
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-87014 — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes