CVE-2026-87626: Incorrect authorization in Google Chrome
CVE-2026-87626 is a medium severity vulnerability in Google Chrome prior to version 153.0.8010.36. It involves incorrect authorization in the DeviceBoundSessionCredentials component, allowing a remote attacker to bypass the web origin policy via crafted network traffic. This flaw could potentially enable unauthorized access to web resources that should be restricted by origin policies.
AI Analysis
Technical Summary
This vulnerability in Google Chrome's DeviceBoundSessionCredentials allows an attacker to bypass the web origin policy due to incorrect authorization checks. The issue affects versions prior to 153.0.8010.36. The web origin policy is a critical security mechanism that restricts how documents or scripts loaded from one origin can interact with resources from another origin. Bypassing this policy can lead to unauthorized access to sensitive data or actions across origins. The vulnerability was publicly disclosed with medium severity and no CVSS score assigned. There is a vendor advisory linked to a stable channel update for Chrome, indicating that a fixed version is available.
Potential Impact
A remote attacker can bypass the web origin policy, potentially allowing unauthorized access to web resources or data that should be isolated by origin boundaries. This could lead to information disclosure or unauthorized actions within the browser context. However, the severity is rated medium, indicating that the impact is significant but not critical.
Mitigation Recommendations
Google has released an update fixing this vulnerability in Chrome version 153.0.8010.36. Users and administrators should update to this version or later to remediate the issue. Since this is not a cloud service, remediation requires applying the browser update. No additional mitigation is indicated by the vendor advisory.
CVE-2026-87626: Incorrect authorization in Google Chrome
Description
CVE-2026-87626 is a medium severity vulnerability in Google Chrome prior to version 153.0.8010.36. It involves incorrect authorization in the DeviceBoundSessionCredentials component, allowing a remote attacker to bypass the web origin policy via crafted network traffic. This flaw could potentially enable unauthorized access to web resources that should be restricted by origin policies.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Google Chrome's DeviceBoundSessionCredentials allows an attacker to bypass the web origin policy due to incorrect authorization checks. The issue affects versions prior to 153.0.8010.36. The web origin policy is a critical security mechanism that restricts how documents or scripts loaded from one origin can interact with resources from another origin. Bypassing this policy can lead to unauthorized access to sensitive data or actions across origins. The vulnerability was publicly disclosed with medium severity and no CVSS score assigned. There is a vendor advisory linked to a stable channel update for Chrome, indicating that a fixed version is available.
Potential Impact
A remote attacker can bypass the web origin policy, potentially allowing unauthorized access to web resources or data that should be isolated by origin boundaries. This could lead to information disclosure or unauthorized actions within the browser context. However, the severity is rated medium, indicating that the impact is significant but not critical.
Mitigation Recommendations
Google has released an update fixing this vulnerability in Chrome version 153.0.8010.36. Users and administrators should update to this version or later to remediate the issue. Since this is not a cloud service, remediation requires applying the browser update. No additional mitigation is indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-09-08T22:43:05.013Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","vendor":"Google"}]
Threat ID: 6aa0b192acd9273b49812ade
Added to database: 09/09/2026, 01:08:34 UTC
Last enriched: 09/09/2026, 01:38:00 UTC
Last updated: 09/09/2026, 02:15:12 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.