ZeroHour

CVE-2026-87506

mass

Sandbox escape via privilege elevation in Google Chrome WebUI

CVSS 3.1
8.3 high
EPSS
<1%p22
Published
()
Modified
AI analysis

Google Chrome versions prior to 153.0.8010.36 contain a privilege elevation flaw (CWE-250) in the WebUI component that allows code to escape the browser sandbox. An attacker triggers it by luring a user to load a crafted HTML page, and the flaw is exploited only after the attacker has already compromised the renderer process, making it a typical second-stage link in a browser exploit chain. Once outside the sandbox, the attacker can potentially execute arbitrary code with privileges beyond the sandbox on the user's system. All Chrome users running unpatched builds are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, the flaw is not yet in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Update Chrome to 153.0.8010.36 or later on all endpoints and verify the installed version via chrome://settings/help with automatic updates enabled. Because exploitation requires a prior renderer-process compromise, treat this patch as part of a chain-defense strategy alongside other Chromium renderer fixes and keep site isolation enabled. Monitor Google's release notes for any scope changes; no specific workarounds are documented.

Affected
google chromeAll versions prior to 153.0.8010.36
Estimated exposure
mass~3+ billion users (Chrome holds roughly 65% of global browser market share) — Estimated from Chrome's dominant global browser market share and multi-billion install base across desktop and mobile endpoints.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege elevation in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-250
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.