
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87658 is an information leak vulnerability in the Extensions component of Google Chrome that allows a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. It affects all versions of Google Chrome prior to 153.0.8010.36 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on March 26, 2026, and publicly disclosed on September 8–9, 2026, as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Github Advisory).
The vulnerability is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-346 (Origin Validation Error), indicating that Chrome's Extensions subsystem fails to properly enforce origin boundaries, allowing a malicious extension to access cross-origin data it should not be permitted to read. Exploitation requires user interaction — specifically, a victim must be socially engineered into installing a crafted malicious Chrome extension. The Chromium issue tracker references bug ID 496615345 for this vulnerability (Github Advisory, Chrome Releases). No public technical write-up or proof-of-concept code has been identified.
Successful exploitation results in a limited confidentiality breach, allowing an attacker to read cross-origin data that should be restricted by the browser's same-origin policy. There is no impact on integrity or availability. The scope of data exposure is constrained to information accessible via the extension's context, but could include sensitive page content, cookies, or other cross-origin resources depending on the extension's granted permissions. Lateral movement potential is low given the browser-sandboxed nature of the vulnerability (Github Advisory, Red Hat Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-87658 as of the time of disclosure (Feedly). The EPSS score is approximately 0.23% (8th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction via social engineering to install a malicious extension (Github Advisory).
<all_urls>) or cross-origin access permissions not consistent with the extension's stated purpose.%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ on Windows or ~/.config/google-chrome/Default/Extensions/ on Linux) corresponding to an unrecognized extension ID.Update Google Chrome to version 153.0.8010.36 or later (153.0.8010.36/.37 on Windows/Mac, 153.0.8010.36 on Linux), which contains the fix for this vulnerability (Chrome Releases). As a complementary measure, organizations should audit installed Chrome extensions for suspicious permissions, restrict extension installation to approved sources via enterprise policy, and educate users about the risks of installing extensions from untrusted sources. No configuration-based workaround is available beyond disabling or restricting extension installation entirely.
The Chrome 153 release was covered by security-focused outlets noting the large number of fixes (230 security issues) in the update, with some coverage highlighting the in-the-wild exploitation of a separate vulnerability (CVE-2026-87491) in the same release (CyberPress). CVE-2026-87658 itself, rated Medium severity, did not attract significant individual commentary given its lower severity relative to the critical and high-severity issues in the same batch. Red Hat and Microsoft both tracked the vulnerability through their respective advisory channels (Red Hat Advisory, Microsoft MSRC).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."