ZeroHour

CVE-2026-87492

mass

Incorrect Authorization in Google Chrome DevTools Could Enable Sandbox-Escape RCE

CVSS 3.1
9.6 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-87492 is an incorrect authorization flaw (CWE-863) in the DevTools component of Google Chrome. A remote attacker could trigger it by persuading a user to open a crafted HTML page, meaning successful exploitation requires user interaction. If exploited, the attacker could potentially execute arbitrary code outside the browser's sandbox, breaching Chrome's key security boundary with high impact on confidentiality, integrity, and availability. All users running Google Chrome prior to 153.0.8010.36 are affected. As of now there is no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no in-the-wild exploitation is known.

What to do: Update Google Chrome to version 153.0.8010.36 or later, verifying the version at chrome://settings/help; enterprise administrators should push the update through their browser update management channels. Because exploitation requires luring users to a malicious page, remind users of safe browsing practices, and treat this critical-rated (CVSS 9.6) sandbox-escape flaw as a high-priority patch even though no public PoC or in-the-wild exploitation is currently known.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of users — effectively the entire Chrome install base on versions before 153.0.8010.36 — Chrome is the world's dominant desktop browser with a user base commonly estimated at over 3 billion, and every installation running a version earlier than 153.0.8010.36 is technically vulnerable until updated.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.