CVE-2026-87509
massSandbox Escape via Incorrect Authorization in Google Chrome Updater on Windows
CVE-2026-87509 is an incorrect authorization flaw (CWE-863) in the updater component of Google Chrome on Windows. A local attacker, already able to run a program on the machine, can leverage the flaw to execute arbitrary code outside Chrome's sandbox. Successful exploitation defeats Chrome's sandbox isolation and yields arbitrary code execution with broader rights on the Windows host, though the local attack vector and high exploitation complexity keep practical risk low. Only Google Chrome on Windows prior to 153.0.8010.36 is affected per the advisory. No public proof-of-concept or in-the-wild exploitation is known; the issue is not in CISA KEV, EPSS assigns just a 0.2% 30-day exploitation probability, and Chromium rates the severity Low despite the High CVSS 8.1 score.
What to do: Update Google Chrome on Windows to 153.0.8010.36 or later, verifying the version via Chrome's About page or your enterprise update-management tooling. Because exploitation requires an existing local program, treat this as defense-in-depth: confirm the Chrome updater service is enabled and auto-updates are functioning. No workarounds or public PoC are known.
| google chrome | Windows versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.