ZeroHour

CVE-2026-87510

mass

Improper Input Validation in Google Chrome FileAPI Enables Sandbox Escape

CVSS 3.1
8.3 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-87510 is an improper input validation flaw (CWE-20) in the FileAPI component of Google Chrome. It is triggered via a crafted HTML page and, per the CVSS vector, requires the attacker to have already compromised the Chrome renderer process before the flaw can be leveraged. A successful exploit lets the attacker execute arbitrary code outside the Chrome sandbox, escalating a renderer-level compromise to broader code execution with high confidentiality, integrity and availability impact. Users running Google Chrome prior to 153.0.8010.36 are affected. There is no known exploitation at this time: no public proof-of-concept, not listed in CISA KEV, and EPSS puts 30-day exploitation probability at 0.3% (22nd percentile).

What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, using enterprise update management to confirm fleet-wide patch levels. Note that this flaw is a sandbox escape requiring a separate renderer compromise, so also prioritize patching any renderer-execution vulnerabilities and caution users about opening untrusted HTML pages.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
mass≈ billions of Chrome users (Chrome holds roughly two-thirds of browser market share with on the order of 3 billion+ users) — Chrome is the world's dominant browser, so installations on vulnerable builds likely number in the billions, though full exploitation additionally requires a prior renderer compromise and user interaction with an attacker-controlled page.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.