CVE-2026-87470
massImproper Quantity Validation in Chrome's Tint on Mac Enables Sandbox-Escaping RCE
CVE-2026-87470 is an improper quantity validation flaw (CWE-1284) in the Tint component of Google Chrome on macOS, fixed in 153.0.8010.36. A remote attacker can trigger it by persuading a user to open a crafted HTML page; no privileges or special access are required beyond that user interaction. Successful exploitation potentially allows arbitrary code execution outside the Chrome browser sandbox, meaning code could run with broader rights on the Mac host rather than being confined to the renderer. Only Chrome on Mac prior to version 153.0.8010.36 is affected per the advisory, and there is currently no known in-the-wild exploitation, no public proof-of-concept, and a low EPSS score of 0.3%. Note that while the published CVSS 3.1 score is 9.6 (critical), the Chromium team rated the underlying bug as Medium severity.
What to do: Update Google Chrome on macOS to 153.0.8010.36 or later (check via Settings > About Chrome, which also triggers auto-update), and verify fleet-wide browser versions in enterprise management tools such as MDM or Chrome Browser Cloud Management. Because the bug is triggered by hostile web content, prompt patching is the primary defense; users on other operating systems should still keep Chrome current but are not indicated as affected by this advisory.
| Google Chrome (macOS) | All versions prior to 153.0.8010.36 on Mac |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper quantity validation in Tint in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-1284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.