Skip to content
Auto-CTI
Back to today
NEW MEDIUM A3

CVE-2026-87513: Missing Authorization in ControlledFrame in Google Chrome Prior to 153.0.8010.36

A NVD · · CVE-2026-87513

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

The vulnerability requires active social engineering manipulation via a crafted HTML page and affects only users who click on malicious links, therefore posing low risk for well-trained users.

Description

An authorization check in the ControlledFrame component of Google Chrome prior to version 153.0.8010.36 is insufficiently implemented. This allows an attacker to bypass system access restrictions through a crafted HTML page and social engineering. The vulnerability has a medium security severity and requires active user interaction (clicking a malicious link). No evidence of active exploitation has been reported so far.

Risk score

0
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC