PatchSiren cyber security CVE debrief
CVE-2026-87580 Google CVE debrief
CVE-2026-87580 is an incorrect authorization vulnerability in WebAppInstalls in Google Chrome prior to version 153.0.8010.36. This vulnerability allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. The Chromium security severity is rated as Medium with a CVSS score of 6.5.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-09
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-09
- Advisory updated
- 2026-09-11
Who should care
Defenders who manage Google Chrome deployments should assess exposure and prioritize updating to version 153.0.8010.36 or later. Additionally, users who interact with Google Chrome should be educated about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.
Why it matters
CVE-2026-87580 is a medium-severity vulnerability in Google Chrome that allows a remote attacker to bypass site isolation via social engineering. Defenders should prioritize updating Google Chrome and educating users about social engineering risks.
- Defenders need to verify if their Google Chrome deployments are updated to version 153.0.8010.36 or later.
- Defenders should educate users about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.
- Defenders need to implement additional security measures to prevent social engineering attacks.
Technical summary
The vulnerability is caused by incorrect authorization in WebAppInstalls in Google Chrome prior to version 153.0.8010.36. This allows a remote attacker who has compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. Defenders should prioritize updating Google Chrome to version 153.0.8010.36 or later to mitigate this vulnerability. Additionally, defenders should educate users about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.
Defensive priority
Defenders should prioritize updating Google Chrome to version 153.0.8010.36 or later to mitigate this vulnerability. Additionally, defenders should educate users about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.
Recommended defensive actions
- Update Google Chrome to version 153.0.8010.36 or later
- Educate users about the risks of social engineering
- Implement additional security measures to prevent social engineering attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD vulnerability detail provide information about the incorrect authorization vulnerability in WebAppInstalls in Google Chrome. The vendor advisory and release notes provide additional context about the vulnerability and the available patch.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87580 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87580
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87580 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87580
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
[email protected] - Vendor Advisory, Release Notes
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/502986244
[email protected] - Exploit, Issue Tracking, Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.