ZeroHour

CVE-2026-87509

mass

Sandbox Escape via Incorrect Authorization in Google Chrome Updater on Windows

CVSS 3.1
8.1 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-87509 is an incorrect authorization flaw (CWE-863) in the updater component of Google Chrome on Windows. A local attacker, already able to run a program on the machine, can leverage the flaw to execute arbitrary code outside Chrome's sandbox. Successful exploitation defeats Chrome's sandbox isolation and yields arbitrary code execution with broader rights on the Windows host, though the local attack vector and high exploitation complexity keep practical risk low. Only Google Chrome on Windows prior to 153.0.8010.36 is affected per the advisory. No public proof-of-concept or in-the-wild exploitation is known; the issue is not in CISA KEV, EPSS assigns just a 0.2% 30-day exploitation probability, and Chromium rates the severity Low despite the High CVSS 8.1 score.

What to do: Update Google Chrome on Windows to 153.0.8010.36 or later, verifying the version via Chrome's About page or your enterprise update-management tooling. Because exploitation requires an existing local program, treat this as defense-in-depth: confirm the Chrome updater service is enabled and auto-updates are functioning. No workarounds or public PoC are known.

Affected
google chromeWindows versions prior to 153.0.8010.36
Estimated exposure
mass≈1–2 billion Windows Chrome installations (Chrome has ~3B+ users, predominantly on Windows desktops) — Chrome is the dominant desktop browser and the updater ships with every Windows installation, though the local-only attack vector means an attacker must already run a program on the endpoint, limiting practical exploitability to hosts with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.