CVE-2026-87479
massExtension Policy Enforcement Flaw Enables Sandbox Escape in Google Chrome
Google Chrome prior to 153.0.8010.36 contains an insufficient policy enforcement flaw in its Extensions component (CWE-807), rated Medium by Chromium. It is triggered remotely via a crafted HTML page, but only after the attacker has already compromised the Chrome renderer process and uses social engineering to induce the required user interaction. If successful, the attacker can execute arbitrary code outside the Chrome sandbox, defeating the browser's strongest isolation layer. All users running Chrome versions before 153.0.8010.36 are affected. There are no known in-the-wild exploits or public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the installed version at chrome://settings/help or chrome://version, relying on built-in auto-update. Because the flaw requires an already-compromised renderer plus user interaction, routine patching cadence is adequate for most estates, but prioritize browsers used by high-risk or frequently targeted staff. No public proof-of-concept exists, so no additional workarounds beyond prompt patching are indicated.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-807
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.