CVE-2026-87499
massAuthorization flaw in Google Chrome lets compromised renderer bypass site isolation
CVE-2026-87499 is an incorrect-authorization flaw (CWE-863) in the network component of Google Chrome that fails to properly enforce site isolation. It is triggered remotely when an attacker who has already compromised the browser's renderer process gets the user to load a crafted HTML page, allowing the compromised renderer to cross site-isolation boundaries. Successful exploitation lets the attacker access cross-origin data from other sites loaded in the same browser, undermining the isolation guarantee that normally confines a compromised renderer to one site; confidentiality and integrity are impacted while availability is not. Users running Google Chrome prior to version 153.0.8010.36 are affected. There are currently no known reports of exploitation in the wild, no public proof-of-concept, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later; verify the installed version at chrome://settings/help and confirm auto-updates are enabled. Note that exploitation requires a prior compromise of the renderer process, so this flaw is most likely chained with another browser bug rather than used standalone; patching removes it as a second stage in such attack chains.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.