Unintended Proxy or Intermediary in Google Chromium - CVE-2026-87502
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause the browser to perform unauthorized actions.
The vulnerability exists due to a confused deputy condition in the Fullscreen feature when handling fullscreen requests. A remote attacker can trick a victim into interacting with fullscreen content to cause the browser to perform unauthorized actions.
Affected software
Google Chrome
How to mitigate CVE-2026-87502
Google Chrome - update to 153.0.8010.36