Skip to content
Auto-CTI
Back to today
NEW MEDIUM A3

CVE-2026-87443: Missing Authorization in Google Chrome Prior to 153.0.8010.36 Allows Remote Information Disclosure

A NVD · · CVE-2026-87443

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

An authorization flaw in Chrome allows attackers to extract sensitive information via crafted HTML pages, with no active exploitation in the wild currently reported.

Description

CVE-2026-87443 is an authorization flaw in Google Chrome prior to version 153.0.8010.36 that allows attackers to obtain sensitive information via a crafted HTML page. The vulnerability is rated with medium severity (Chromium security rating: Medium). The attack is remote and requires no user interaction beyond visiting a malicious page. There are currently no reports of active exploitation in the wild.

Risk score

0
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC