ZeroHour

CVE-2026-87487

mass

Missing Authorization Sandbox Escape in Google Chrome FileSystem

CVSS 3.1
8.3 high
EPSS
<1%p35
Published
()
Modified
AI analysis

CVE-2026-87487 is a missing-authorization flaw (CWE-862) in the FileSystem component of Google Chrome, where permission checks are not properly enforced. To exploit it, a remote attacker must first compromise the Chrome renderer process and then leverage social engineering via a crafted HTML page, presumably to obtain the user's approval for filesystem access. If successful, the attacker can potentially execute arbitrary code outside the Chrome sandbox, breaking out of the browser's security isolation with high impact on confidentiality, integrity, and availability; Chromium rates the issue Medium while CVSS 3.1 assigns it 8.3 (High). All Chrome users running versions prior to 153.0.8010.36 are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints and verify the patched build is actually running (e.g., via chrome://version), since auto-updates can lag on some machines. Because exploitation requires a chained renderer compromise plus user interaction under social engineering, standard patch cadence and user caution around unexpected filesystem permission prompts from web pages are reasonable interim mitigations. Managed environments should confirm their update policies push the fixed build promptly.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
mass~3+ billion Chrome installations — Chrome is the world's most widely used browser, with publicly estimated global usage in the billions of devices, and the flaw applies to every build released before the 153.0.8010.36 fix.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.