ZeroHour

CVE-2026-87493

PoC mass

Missing Authorization in Google Chrome FileSystem Enables Access-Restriction Bypass

CVSS 3.1
6.5 medium
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-87493 is a missing-authorization flaw (CWE-862) in the FileSystem component of Google Chrome, rated Medium severity by Chromium. A remote attacker can trigger it by using social engineering to lure a user into opening a crafted HTML page, with user interaction required before the flaw is reached. Successful exploitation bypasses system access restrictions on the filesystem, and the CVSS scoring indicates the practical impact is a high loss of integrity (unauthorized changes) with no confidentiality or availability impact. Any user running Google Chrome prior to 153.0.8010.36 is affected. A public proof-of-concept is available via the Chromium issue tracker, but exploitation probability is low (EPSS 0.2%) and the flaw is not in the CISA KEV catalog, with no confirmed in-the-wild attacks reported.

What to do: Update Google Chrome to 153.0.8010.36 or later (via Help > About Google Chrome, or your enterprise update channel) and verify fleet versions through browser management tooling. Until patched, caution users against opening untrusted HTML pages and be wary of unexpected file-system permission prompts. Given the low EPSS score and Medium severity, this can be handled in the normal patch cycle rather than as an emergency.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome's installed base is roughly 3+ billion; every install older than 153.0.8010.36 is affected) — Chrome is the world's most widely used browser with on the order of 3 billion users per public usage statistics, and the affected range spans all builds before 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.