CVE-2026-87441 Details
Description
Missing authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
A vulnerability in Google Chrome's Downloads API prior to version 153.0.8010.36 allowed remote attackers to bypass authorization restrictions through a malicious Chrome extension. The flaw arose because certain functions in the Downloads extension API did not properly verify if a download item should be accessible to extensions. This oversight enabled attackers to manipulate internal browser downloads, such as those related to Web Store extension installations, by guessing download IDs and using action APIs to disrupt or delete these files.
Users should update Google Chrome to version 153.0.8010.36 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html | [email protected] | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/514556469 | [email protected] | ExploitIssue TrackingMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 153.0.8010.36 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | Initial Analysis | [email protected] |
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |