Missing Authorization in Google Chromium - CVE-2026-87622
Published: September 9, 2026
Vulnerability identifier: #VU148620
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87622
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to missing authorization in FedCM when processing FedCM requests. A remote attacker can induce the victim to interact with web content to perform unauthorized actions.
User interaction is required.
Affected software
Google Chromium
Google Chrome
Google Chrome
How to mitigate CVE-2026-87622
Install security update from vendor's website.
Google Chromium - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36