CVE-2026-87551

Summary

Improper certificate validation in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: Low)

Affected Software

VendorProductVersion RangeStatus
GoogleChrome153.0.8010.36 < 153.0.8010.36affected

Weaknesses

  • CWE-295: Improper certificate validation

References