Incorrect authorization in Google Chromium - CVE-2026-87626
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to access DeviceBoundSessionCredentials without authorization.
The vulnerability exists due to incorrect authorization in DeviceBoundSessionCredentials when performing authorization checks. A remote attacker can trigger the flawed authorization check to access DeviceBoundSessionCredentials without authorization.
User interaction is required.
Affected software
Google Chrome
How to mitigate CVE-2026-87626
Google Chrome - update to 153.0.8010.36