Missing Authorization in Google Chromium - CVE-2026-87631
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to access restricted DOM resources.
The vulnerability exists due to missing authorization in the DOM when rendering crafted web content. A remote attacker can induce a victim to render crafted web content to access restricted DOM resources.
User interaction is required to render crafted web content.
Affected software
Google Chrome
How to mitigate CVE-2026-87631
Google Chrome - update to 153.0.8010.36