ZeroHour

CVE-2026-87468

PoC mass

Site Isolation Bypass in Google Chrome via Incorrect Authorization

CVSS 3.1
6.5 medium
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-87468 is an incorrect authorization flaw (CWE-863) in the site isolation ('Isolated') component of Google Chrome. A remote attacker can trigger it by persuading a user to open a crafted HTML page, since the attack vector requires user interaction. Successful exploitation lets the attacker bypass Chrome's site isolation protections, undermining the browser's cross-site separation guarantees; the CVSS vector (C:N/I:H/A:N) characterizes this as a high-integrity issue with no confidentiality or availability impact. All users running Google Chrome prior to 153.0.8010.36 are affected. The flaw is rated Medium (CVSS 6.5) with a low exploitation probability (EPSS 0.2%, 7th percentile), is not in CISA's KEV catalog, and has a public proof-of-concept reference in the Chromium issue tracker but no confirmed in-the-wild exploitation.

What to do: Update Google Chrome to version 153.0.8010.36 or later and verify the running version at chrome://version, including managed/auto-update fleets. Until patched, exercise caution with untrusted HTML pages; no in-the-wild exploitation is confirmed, but the public proof-of-concept makes timely patching prudent.

Affected
Google Chromeall versions prior to 153.0.8010.36 (fixed in 153.0.8010.36)
Estimated exposure
mass≈3+ billion active Chrome installations worldwide (only unpatched versions below 153.0.8010.36 are vulnerable) — Chrome is the world's dominant desktop browser with roughly two-thirds of browser usage per public market-share analytics, implying billions of installations, though the vulnerable population is limited to versions prior to 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.