Missing Authorization in Google Chromium - CVE-2026-87557

 

Missing Authorization in Google Chromium - CVE-2026-87557

Published: September 9, 2026


Vulnerability identifier: #VU148554
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87557
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access local network resources without authorization.

The vulnerability exists due to missing authorization in LocalNetworkAccess when handling crafted web content. A remote attacker can induce the victim to interact with crafted web content to access local network resources without authorization.

User interaction is required.


Affected software

Google Chromium
Google Chrome

How to mitigate CVE-2026-87557

Install security update from vendor's website.

Google Chromium - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36

External References

Related Security Bulletins