Missing Authorization in Google Chromium - CVE-2026-87475
Published: September 9, 2026
Vulnerability identifier: #VU148578
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87475
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in Omnibox when processing omnibox input. A remote attacker can cause input to be processed without required authorization checks to perform unauthorized actions.
User interaction is required.
Affected software
Google Chromium
Google Chrome
Google Chrome
How to mitigate CVE-2026-87475
Install security update from vendor's website.
Google Chromium - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36