CVE-2026-87433
massRace Condition in Google Chrome FileAPI Bypasses Site Isolation
A race condition (TOCTOU, CWE-367) in the FileAPI component of Google Chrome allowed an attacker who had already compromised the renderer process to bypass site isolation via a crafted HTML page. This means a bug normally confined to one site's sandboxed renderer could be leveraged to reach data and resources belonging to other sites, weakening one of Chrome's core defense-in-depth boundaries. All users running Google Chrome prior to 153.0.8010.36 are affected. Although the CVSS 3.1 score is 8.8 (High), Chromium rated the flaw Medium severity because it requires a prior renderer compromise rather than working standalone. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later via Menu > Help > About Google Chrome and restart the browser; enterprise admins should verify deployed versions fleet-wide using their update-management tooling. Because the flaw only becomes exploitable after a renderer compromise, keeping Chrome fully current and relying on its bundled sandbox and site-isolation defenses is the primary mitigation, and no workarounds are known.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Race condition in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.