ZeroHour

CVE-2026-87471

mass

Site Isolation Bypass via Incorrect Authorization in Google Chrome ServiceWorker

CVSS 3.1
8.1 high
EPSS
<1%p22
Published
()
Modified
AI analysis

Google Chrome versions prior to 153.0.8010.36 contain an incorrect authorization flaw (CWE-863) in the browser's ServiceWorker implementation. An attacker who has already compromised a renderer process must get a crafted HTML page loaded (user interaction is required) and can then abuse the flawed ServiceWorker authorization checks to bypass Chrome's site isolation. Successful bypassing of site isolation exposes cross-origin data from other open sites to the attacker, which CVSS scores as high confidentiality and integrity impact (8.1). All Chrome users running builds before 153.0.8010.36 are affected, and because the defect resides in shared Chromium code, other Chromium-based browsers may also be impacted when their maintainers ship the underlying fix. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to 153.0.8010.36 or later and verify the build via Settings > About Chrome or chrome://version; enforce the update across managed fleets via browser update policies. Users of other Chromium-based browsers (e.g., Edge, Brave, Opera) should apply their vendor's next Chromium-derived security update. Because exploitation requires an already-compromised renderer process, prompt patching plus standard browser hardening are the primary mitigations; no standalone workaround is known.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
masshundreds of millions of unpatched installs (Chrome's user base is roughly 3 billion; all pre-153.0.8010.36 builds are vulnerable until auto-update lands) — Chrome's worldwide installed base is on the order of billions, and in the days-to-weeks after a fixed release the unpatched share of installs typically numbers in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.