Missing Authorization in Google Chromium - CVE-2026-87603
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization controls for the FileSystem.
The vulnerability exists due to missing authorization checks in the FileSystem when a victim interacts with affected FileSystem functionality. A remote attacker can cause a victim to interact with the affected FileSystem functionality to bypass authorization controls for the FileSystem.
User interaction is required.
Affected software
Google Chrome
How to mitigate CVE-2026-87603
Google Chrome - update to 153.0.8010.36