ZeroHour

CVE-2026-87505

PoC mass

Incorrect Authorization in Google Chrome FileSystem Enables Site Isolation Bypass

CVSS 3.1
8.1 high
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-87505 is an incorrect-authorization flaw (CWE-863) in the FileSystem component of Google Chrome that allows an attacker to bypass the browser's site isolation boundaries. It is triggered when a remote attacker who has already compromised a Chrome renderer process induces the browser to process a crafted PDF file. Having bypassed site isolation, the attacker gains unauthorized access across origin boundaries, with the CVSS vector indicating high confidentiality and integrity impact. Anyone running Google Chrome prior to 153.0.8010.36 is affected; Google's Chromium severity rating is Medium, while the CVSS 3.1 base score is 8.1 (high). No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS assigns a 0.2% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later and restart the browser to ensure the patched build is loaded (progress can be checked via chrome://settings/help). Because exploitation requires an already-compromised renderer process, promptly patching renderer-targeting flaws—particularly PDF processing bugs—reduces the risk of the prerequisite renderer compromise. Keep Chrome's auto-update and default site isolation settings enabled while monitoring for any published proof-of-concept.

Affected
Google Chromeprior to 153.0.8010.36 (fixed in 153.0.8010.36)
Estimated exposure
mass≈3 billion users (Chrome's installed base at roughly two-thirds of desktop browser usage share) — Chrome holds approximately 65% of desktop browser usage share per public market-share trackers, implying an installed base in the billions, of which all desktop users on pre-153.0.8010.36 builds were affected until auto-update delivered…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.