Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Published 8 Sep 2026Updated 10 Sep 20266 sources
CVSS 5.4 ✓ VERIFIED REFERENCE

What happened

Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)

Affected versions

Chrome: 153.0.8010.36 through before 153.0.8010.36 (custom) Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references