CVE-2026-87487
massMissing Authorization Sandbox Escape in Google Chrome FileSystem
CVE-2026-87487 is a missing-authorization flaw (CWE-862) in the FileSystem component of Google Chrome, where permission checks are not properly enforced. To exploit it, a remote attacker must first compromise the Chrome renderer process and then leverage social engineering via a crafted HTML page, presumably to obtain the user's approval for filesystem access. If successful, the attacker can potentially execute arbitrary code outside the Chrome sandbox, breaking out of the browser's security isolation with high impact on confidentiality, integrity, and availability; Chromium rates the issue Medium while CVSS 3.1 assigns it 8.3 (High). All Chrome users running versions prior to 153.0.8010.36 are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only about a 0.3% probability of exploitation within 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints and verify the patched build is actually running (e.g., via chrome://version), since auto-updates can lag on some machines. Because exploitation requires a chained renderer compromise plus user interaction under social engineering, standard patch cadence and user caution around unexpected filesystem permission prompts from web pages are reasonable interim mitigations. Managed environments should confirm their update policies push the fixed build promptly.
| Google Chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.