CVE-2026-87645: Improper state validation in Google Chrome
CVE-2026-87645 is a medium severity vulnerability in Google Chrome's Safebrowsing feature prior to version 153.0.8010.36. It involves improper state validation that allows a remote attacker to bypass system access restrictions by using a crafted HTML page. There is no CVSS score available for this vulnerability. The vendor advisory linked indicates a stable channel update addressing this issue.
AI Analysis
Technical Summary
This vulnerability in Google Chrome affects the Safebrowsing component, where improper state validation can be exploited by a remote attacker to bypass system access restrictions through a specially crafted HTML page. The issue affects versions before 153.0.8010.36. The vulnerability is classified with medium severity by Chromium security. No detailed CVSS vector is provided. The vendor has released an update in Chrome version 153.0.8010.36 to address this issue.
Potential Impact
An attacker can bypass system access restrictions remotely by exploiting the improper state validation in Safebrowsing, potentially allowing unauthorized actions that should be restricted by the system. The impact is limited to the scope of Safebrowsing and the specific bypass of access controls, rated medium severity by the vendor.
Mitigation Recommendations
Update Google Chrome to version 153.0.8010.36 or later, where this vulnerability has been fixed. The vendor advisory confirms the availability of a stable channel update addressing this issue. Users should apply this update promptly to mitigate the risk.
CVE-2026-87645: Improper state validation in Google Chrome
Description
CVE-2026-87645 is a medium severity vulnerability in Google Chrome's Safebrowsing feature prior to version 153.0.8010.36. It involves improper state validation that allows a remote attacker to bypass system access restrictions by using a crafted HTML page. There is no CVSS score available for this vulnerability. The vendor advisory linked indicates a stable channel update addressing this issue.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Google Chrome affects the Safebrowsing component, where improper state validation can be exploited by a remote attacker to bypass system access restrictions through a specially crafted HTML page. The issue affects versions before 153.0.8010.36. The vulnerability is classified with medium severity by Chromium security. No detailed CVSS vector is provided. The vendor has released an update in Chrome version 153.0.8010.36 to address this issue.
Potential Impact
An attacker can bypass system access restrictions remotely by exploiting the improper state validation in Safebrowsing, potentially allowing unauthorized actions that should be restricted by the system. The impact is limited to the scope of Safebrowsing and the specific bypass of access controls, rated medium severity by the vendor.
Mitigation Recommendations
Update Google Chrome to version 153.0.8010.36 or later, where this vulnerability has been fixed. The vendor advisory confirms the availability of a stable channel update addressing this issue. Users should apply this update promptly to mitigate the risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-09-08T22:43:54.074Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html","vendor":"Google"}]
Threat ID: 6aa0b196acd9273b49812b57
Added to database: 09/09/2026, 01:08:38 UTC
Last enriched: 09/09/2026, 01:23:03 UTC
Last updated: 09/09/2026, 01:23:03 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.