CVE-2026-87471
massSite Isolation Bypass via Incorrect Authorization in Google Chrome ServiceWorker
Google Chrome versions prior to 153.0.8010.36 contain an incorrect authorization flaw (CWE-863) in the browser's ServiceWorker implementation. An attacker who has already compromised a renderer process must get a crafted HTML page loaded (user interaction is required) and can then abuse the flawed ServiceWorker authorization checks to bypass Chrome's site isolation. Successful bypassing of site isolation exposes cross-origin data from other open sites to the attacker, which CVSS scores as high confidentiality and integrity impact (8.1). All Chrome users running builds before 153.0.8010.36 are affected, and because the defect resides in shared Chromium code, other Chromium-based browsers may also be impacted when their maintainers ship the underlying fix. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the build via Settings > About Chrome or chrome://version; enforce the update across managed fleets via browser update policies. Users of other Chromium-based browsers (e.g., Edge, Brave, Opera) should apply their vendor's next Chromium-derived security update. Because exploitation requires an already-compromised renderer process, prompt patching plus standard browser hardening are the primary mitigations; no standalone workaround is known.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.