CVE-2026-87610
Incorrect authorization in Omnibox in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Scoring
- CVSS base score
- 1.5
- CWE
- CWE-863
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-86773 — Snipe-IT 8.6.3 Broken Access Control via Kit Update Endpoints
- CVE-2026-86760 — snipe-it 8.2.0 before 8.7.0 Authentication Bypass via activated flag
- CVE-2026-86755 — Snipe-IT 4.2.0 through 8.6.3 Permission Bypass via OAuth
- CVE-2026-86754 — Snipe-IT before 8.7.0 Authorization Bypass via OAuth Clients
- CVE-2026-86753 — snipe-it before 8.7.0 Business Logic Bypass via asset_model endpoint
- CVE-2026-86752 — snipe-it before 8.7.0 Authorization Bypass via Asset Audit Endpoints
- CVE-2026-86750 — snipe-it before 8.7.0 Authorization Bypass via API User Create/Update
- CVE-2026-86747 — snipe-it before 8.7.0 Authorization Bypass via Pivot-Only User