SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-87644

HIGH · CVSS 8.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

Google Chrome on Windows versions prior to 153.0.8010.36 is vulnerable due to incorrect authorization in the Views component, which could allow a remote attacker to execute arbitrary code outside the sandbox by exploiting a compromised renderer process through social engineering tactics. Organizations using affected versions of Chrome should prioritize patching this vulnerability to mitigate potential risks of unauthorized code execution. Users and administrators should remain vigilant against social engineering attempts that could facilitate this attack.

CVE
CVE-2026-87644
Severity
HIGH
CVSS
8.3
EPSS
0.27%
Windows Chrome

Original NVD Description

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)