CVE-2026-87561
Incorrect authorization in Web Authentication in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
Scoring
- CVSS base score
- 1.5
- EPSS probability
- 0.21%
- CWE
- CWE-863
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-88894 — Snipe-IT before 8.7.2 Authorization Bypass via Predefined Kit Checkout
- CVE-2026-88884 — Renovate before 44.3.1 Authentication Bypass via Digest Updates
- CVE-2026-88862 — Capgo API Key Manager Authentication Bypass via x-limited-key-id
- CVE-2026-88860 — Capgo Authorization Bypass via Stale Channel Permission Overrides
- CVE-2026-87803 — An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed...
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-87014 — Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes