CVE-2026-87510
massImproper Input Validation in Google Chrome FileAPI Enables Sandbox Escape
CVE-2026-87510 is an improper input validation flaw (CWE-20) in the FileAPI component of Google Chrome. It is triggered via a crafted HTML page and, per the CVSS vector, requires the attacker to have already compromised the Chrome renderer process before the flaw can be leveraged. A successful exploit lets the attacker execute arbitrary code outside the Chrome sandbox, escalating a renderer-level compromise to broader code execution with high confidentiality, integrity and availability impact. Users running Google Chrome prior to 153.0.8010.36 are affected. There is no known exploitation at this time: no public proof-of-concept, not listed in CISA KEV, and EPSS puts 30-day exploitation probability at 0.3% (22nd percentile).
What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, using enterprise update management to confirm fleet-wide patch levels. Note that this flaw is a sandbox escape requiring a separate renderer compromise, so also prioritize patching any renderer-execution vulnerabilities and caution users about opening untrusted HTML pages.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.