CVE-2026-87519 | Incorrect Authorization in Google Chrome Safe Browsing Prior to 153.0.8010.36
A NVD · · CVE-2026-87519
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- EPSS
- 0%
Key insight
The vulnerability requires active social-engineering manipulation via a crafted HTML page and is rated Low-Severity; operational priority is low, but regular Chrome updates should be enforced.
Description
Google Chrome prior to version 153.0.8010.36 contains a vulnerability in the Safe Browsing function characterized by incorrect authorization checks. An attacker can exploit this flaw via social engineering by creating a specially crafted HTML page and tricking a user into opening it. This allows the attacker to bypass system access restrictions. The Chromium security rating classifies the risk as Low, suggesting that successful exploitation requires additional hurdles or specific conditions. There are no reports of active exploitation in the wild.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational