CVE-2026-87505
PoC massIncorrect Authorization in Google Chrome FileSystem Enables Site Isolation Bypass
CVE-2026-87505 is an incorrect-authorization flaw (CWE-863) in the FileSystem component of Google Chrome that allows an attacker to bypass the browser's site isolation boundaries. It is triggered when a remote attacker who has already compromised a Chrome renderer process induces the browser to process a crafted PDF file. Having bypassed site isolation, the attacker gains unauthorized access across origin boundaries, with the CVSS vector indicating high confidentiality and integrity impact. Anyone running Google Chrome prior to 153.0.8010.36 is affected; Google's Chromium severity rating is Medium, while the CVSS 3.1 base score is 8.1 (high). No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is currently known, and EPSS assigns a 0.2% probability of exploitation within 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later and restart the browser to ensure the patched build is loaded (progress can be checked via chrome://settings/help). Because exploitation requires an already-compromised renderer process, promptly patching renderer-targeting flaws—particularly PDF processing bugs—reduces the risk of the prerequisite renderer compromise. Keep Chrome's auto-update and default site isolation settings enabled while monitoring for any published proof-of-concept.
| Google Chrome | prior to 153.0.8010.36 (fixed in 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.