CVE-2026-87515
PoC massIncorrect Authorization in Google Chrome FileAPI Allows Access Restriction Bypass
Google Chrome versions prior to 153.0.8010.36 contain an incorrect authorization flaw (CWE-863) in the browser's FileAPI that allows access restrictions to be bypassed. A remote attacker triggers it through social engineering, convincing a user to open a crafted HTML page, so exploitation requires user interaction and no privileges or special conditions. On success, the attacker gains an unauthorized bypass of system access restrictions, which CVSS reflects as a high integrity impact with no direct confidentiality or availability loss. All users running an affected Chrome release before the fix are in scope, since no deployment subset is exempt from the flaw's trigger. Exploitation has not been reported in the wild: the flaw is not in CISA KEV, EPSS estimates about 0.2% probability of exploitation within 30 days, and there is one public reference (the Chromium issue tracker).
What to do: Update Chrome to 153.0.8010.36 or later on all endpoints, using enterprise update management and fleet version reporting to confirm no managed devices remain on older builds. Because exploitation depends on user interaction, remind users to be cautious about opening HTML pages from untrusted sources until patching is complete. Patched versions have no known remaining exposure to this flaw.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.