CVE-2026-87468
PoC massSite Isolation Bypass in Google Chrome via Incorrect Authorization
CVE-2026-87468 is an incorrect authorization flaw (CWE-863) in the site isolation ('Isolated') component of Google Chrome. A remote attacker can trigger it by persuading a user to open a crafted HTML page, since the attack vector requires user interaction. Successful exploitation lets the attacker bypass Chrome's site isolation protections, undermining the browser's cross-site separation guarantees; the CVSS vector (C:N/I:H/A:N) characterizes this as a high-integrity issue with no confidentiality or availability impact. All users running Google Chrome prior to 153.0.8010.36 are affected. The flaw is rated Medium (CVSS 6.5) with a low exploitation probability (EPSS 0.2%, 7th percentile), is not in CISA's KEV catalog, and has a public proof-of-concept reference in the Chromium issue tracker but no confirmed in-the-wild exploitation.
What to do: Update Google Chrome to version 153.0.8010.36 or later and verify the running version at chrome://version, including managed/auto-update fleets. Until patched, exercise caution with untrusted HTML pages; no in-the-wild exploitation is confirmed, but the public proof-of-concept makes timely patching prudent.
| Google Chrome | all versions prior to 153.0.8010.36 (fixed in 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.