Incorrect authorization in Google Chromium - CVE-2026-87481
Published: September 9, 2026
Vulnerability identifier: #VU148556
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87481
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to access resources without authorization.
The vulnerability exists due to incorrect authorization in WebView when processing crafted web content. A remote attacker can cause WebView to process crafted web content to access resources without authorization.
User interaction is required.
Affected software
Google Chromium
Google Chrome
Google Chrome
How to mitigate CVE-2026-87481
Install security update from vendor's website.
Google Chromium - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36