Improper Enforcement of Behavioral Workflow in Google Chromium - CVE-2026-87548

 

Improper Enforcement of Behavioral Workflow in Google Chromium - CVE-2026-87548

Published: September 9, 2026


Vulnerability identifier: #VU148594
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87548
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass intended installer state validation.

The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.

User interaction is required.


Affected software

Google Chromium
Google Chrome

How to mitigate CVE-2026-87548

Install security update from vendor's website.

Google Chromium - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36

External References

Related Security Bulletins