CVE-2026-87658
NONECVE-2026-87658: Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin ...
Description
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
CVSS Scores
EPSS Score
Higher than 8% of all CVEs
Threat actors associated with CVE-2026-87658
Kaitan ID has linked 1 threat actor to this vulnerability based on exploit usage, campaign attribution, and intelligence reporting.
- Earth Lusca (China) — also known as CHROMIUM, ControlX, TAG-22, FISHMONGER — exploits (confidence: medium)
Exploit maturity
Disclosed — This vulnerability has been publicly disclosed but no exploit code has been observed yet.
- No vendor patch available yet.
Exploitation probability (EPSS)
EPSS exploitation probability: 0.2% (remained stable from 0.2%, 0% change). This vulnerability ranks in the top 92% of all CVEs by exploitation likelihood. Last updated on Sep 15, 2026.
Other vulnerabilities affecting Microsoft Security Response Center
CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Sep 14, 2026
CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Sep 11, 2026
CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Sep 11, 2026
Chromium: CVE-2025-2137 Out of bounds read in V8
Sep 11, 2026
Chromium: CVE-2025-1920 Type Confusion in V8
Sep 11, 2026
CVE-2026-87657: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside ...
Sep 9, 2026
Primary source
Original advisory or reference for this vulnerability (via NVD).
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html