CVE-2026-87614
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)
Scoring
- CVSS base score
- 1.5
- CWE
- CWE-863
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- Google Chrome
Weakness type
Related vulnerabilities
- CVE-2026-85978 — Unauthenticated Remote Code Execution in Akana API Platform
- CVE-2026-14892 — Tanium addressed an improper access controls vulnerability in Tanium Server.
- CVE-2026-87046 — Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87075 — Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87544 — Incorrect authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87575 — Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87473 — Incorrect authorization in FileHandling in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87509 — Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a...