PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87580 Google CVE debrief

CVE-2026-87580 is an incorrect authorization vulnerability in WebAppInstalls in Google Chrome prior to version 153.0.8010.36. This vulnerability allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. The Chromium security severity is rated as Medium with a CVSS score of 6.5.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-11
Advisory published
2026-09-09
Advisory updated
2026-09-11

Who should care

Defenders who manage Google Chrome deployments should assess exposure and prioritize updating to version 153.0.8010.36 or later. Additionally, users who interact with Google Chrome should be educated about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.

Why it matters

CVE-2026-87580 is a medium-severity vulnerability in Google Chrome that allows a remote attacker to bypass site isolation via social engineering. Defenders should prioritize updating Google Chrome and educating users about social engineering risks.

  • Defenders need to verify if their Google Chrome deployments are updated to version 153.0.8010.36 or later.
  • Defenders should educate users about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.
  • Defenders need to implement additional security measures to prevent social engineering attacks.

Technical summary

The vulnerability is caused by incorrect authorization in WebAppInstalls in Google Chrome prior to version 153.0.8010.36. This allows a remote attacker who has compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. Defenders should prioritize updating Google Chrome to version 153.0.8010.36 or later to mitigate this vulnerability. Additionally, defenders should educate users about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.

Defensive priority

Defenders should prioritize updating Google Chrome to version 153.0.8010.36 or later to mitigate this vulnerability. Additionally, defenders should educate users about the risks of social engineering and the importance of being cautious when interacting with crafted HTML pages.

Recommended defensive actions

  • Update Google Chrome to version 153.0.8010.36 or later
  • Educate users about the risks of social engineering
  • Implement additional security measures to prevent social engineering attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD vulnerability detail provide information about the incorrect authorization vulnerability in WebAppInstalls in Google Chrome. The vendor advisory and release notes provide additional context about the vulnerability and the available patch.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87580 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87580

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87580 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87580

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html

    [email protected] - Vendor Advisory, Release Notes

  • Source reference

    Unverified legacy reference

    URL: https://issues.chromium.org/issues/502986244

    [email protected] - Exploit, Issue Tracking, Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.