ZeroHour

CVE-2026-87499

mass

Authorization flaw in Google Chrome lets compromised renderer bypass site isolation

CVSS 3.1
8.1 high
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-87499 is an incorrect-authorization flaw (CWE-863) in the network component of Google Chrome that fails to properly enforce site isolation. It is triggered remotely when an attacker who has already compromised the browser's renderer process gets the user to load a crafted HTML page, allowing the compromised renderer to cross site-isolation boundaries. Successful exploitation lets the attacker access cross-origin data from other sites loaded in the same browser, undermining the isolation guarantee that normally confines a compromised renderer to one site; confidentiality and integrity are impacted while availability is not. Users running Google Chrome prior to version 153.0.8010.36 are affected. There are currently no known reports of exploitation in the wild, no public proof-of-concept, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Update Google Chrome to 153.0.8010.36 or later; verify the installed version at chrome://settings/help and confirm auto-updates are enabled. Note that exploitation requires a prior compromise of the renderer process, so this flaw is most likely chained with another browser bug rather than used standalone; patching removes it as a second stage in such attack chains.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome has 3+ billion users worldwide, with unpatched installs spanning the entire pre-153.0.8010.36 base) — Chrome's roughly 65% desktop browser market share and Google-reported user base of more than 3 billion mean the unpatched population is on the order of billions until the update fully propagates.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.