ZeroHour

CVE-2026-87515

PoC mass

Incorrect Authorization in Google Chrome FileAPI Allows Access Restriction Bypass

CVSS 3.1
6.5 medium
EPSS
<1%p15
Published
()
Modified
AI analysis

Google Chrome versions prior to 153.0.8010.36 contain an incorrect authorization flaw (CWE-863) in the browser's FileAPI that allows access restrictions to be bypassed. A remote attacker triggers it through social engineering, convincing a user to open a crafted HTML page, so exploitation requires user interaction and no privileges or special conditions. On success, the attacker gains an unauthorized bypass of system access restrictions, which CVSS reflects as a high integrity impact with no direct confidentiality or availability loss. All users running an affected Chrome release before the fix are in scope, since no deployment subset is exempt from the flaw's trigger. Exploitation has not been reported in the wild: the flaw is not in CISA KEV, EPSS estimates about 0.2% probability of exploitation within 30 days, and there is one public reference (the Chromium issue tracker).

What to do: Update Chrome to 153.0.8010.36 or later on all endpoints, using enterprise update management and fleet version reporting to confirm no managed devices remain on older builds. Because exploitation depends on user interaction, remind users to be cautious about opening HTML pages from untrusted sources until patching is complete. Patched versions have no known remaining exposure to this flaw.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass~3 billion+ users (Chrome's global install base; every pre-fix build is plausibly affected) — Chrome is publicly reported as the world's most widely used browser with an install base estimated in the low billions, and the flaw applies to all builds before 153.0.8010.36, so the affected population is effectively Chrome's entire user…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.