MEDIUM
chromium-browser: chromium-browser: Incorrect authorization in WebUI
Published Sep 9, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.28%
Description
Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
Affected products
-
Affected
- ≥ 153.0.8010.36, < 153.0.8010.36
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-87584 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2530285 Issue Tracking
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html Vendor AdvisoryRelease Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-74418 Advisory
- https://issues.chromium.org/issues/537466493 ExploitIssue TrackingPatch
- https://nvd.nist.gov/vuln/detail/CVE-2026-87584
- https://www.cve.org/CVERecord?id=CVE-2026-87584
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-87584 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2530285 | Issue Tracking | |
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html | Vendor AdvisoryRelease Notes | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-74418 | Advisory | |
| https://issues.chromium.org/issues/537466493 | ExploitIssue TrackingPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-87584 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-87584 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Sep 9, 2026
Updated Sep 10, 2026
Reserved Sep 8, 2026
Link CVE-2026-87584
CISA Vulnrichment
Updated Sep 10, 2026
GitHub
No data