Missing Authorization in Google Chromium - CVE-2026-87557
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to access local network resources without authorization.
The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.
User interaction is required.
Affected software
Google Chrome
How to mitigate CVE-2026-87557
Google Chrome - update to 153.0.8010.36