CVE-2026-87492
massIncorrect Authorization in Google Chrome DevTools Could Enable Sandbox-Escape RCE
CVE-2026-87492 is an incorrect authorization flaw (CWE-863) in the DevTools component of Google Chrome. A remote attacker could trigger it by persuading a user to open a crafted HTML page, meaning successful exploitation requires user interaction. If exploited, the attacker could potentially execute arbitrary code outside the browser's sandbox, breaching Chrome's key security boundary with high impact on confidentiality, integrity, and availability. All users running Google Chrome prior to 153.0.8010.36 are affected. As of now there is no public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no in-the-wild exploitation is known.
What to do: Update Google Chrome to version 153.0.8010.36 or later, verifying the version at chrome://settings/help; enterprise administrators should push the update through their browser update management channels. Because exploitation requires luring users to a malicious page, remind users of safe browsing practices, and treat this critical-rated (CVSS 9.6) sandbox-escape flaw as a high-priority patch even though no public PoC or in-the-wild exploitation is currently known.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.