Improper Enforcement of Behavioral Workflow in Google Chromium - CVE-2026-87548
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass intended installer state validation.
The vulnerability exists due to improper state validation in the installer when processing installer state. A remote attacker can cause the installer to accept an invalid state to bypass intended installer state validation.
User interaction is required.
Affected software
Google Chrome
How to mitigate CVE-2026-87548
Google Chrome - update to 153.0.8010.36