CVE-2026-87532
PoC massImproper State Validation in Chrome Safebrowsing Enables Access Restriction Bypass
CVE-2026-87532 is an improper state validation flaw (CWE-754) in the Safe Browsing component of Google Chrome, fixed in Chrome 153.0.8010.36. A remote attacker triggers it by luring a user to a crafted HTML page, which the CVSS vector confirms requires network access and user interaction (UI:R). Successful exploitation bypasses system access restrictions, carrying high integrity impact but no direct confidentiality or availability loss, consistent with the Medium severity rating. All Google Chrome users running builds prior to 153.0.8010.36 are affected. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS estimates only a 0.2% probability of exploitation within 30 days (8th percentile), and the single public reference is a proof-of-concept issue in the Chromium tracker.
What to do: Update Google Chrome to version 153.0.8010.36 or later; since Chrome auto-updates, verify the installed version via Settings > About Chrome (chrome://settings/help). Until patched, avoid untrusted or unfamiliar web pages, and administrators should confirm fleet versions via endpoint management and restrict unpatched builds from accessing sensitive resources where feasible.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-754
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.