ZeroHour

CVE-2026-87532

PoC mass

Improper State Validation in Chrome Safebrowsing Enables Access Restriction Bypass

CVSS 3.1
6.5 medium
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-87532 is an improper state validation flaw (CWE-754) in the Safe Browsing component of Google Chrome, fixed in Chrome 153.0.8010.36. A remote attacker triggers it by luring a user to a crafted HTML page, which the CVSS vector confirms requires network access and user interaction (UI:R). Successful exploitation bypasses system access restrictions, carrying high integrity impact but no direct confidentiality or availability loss, consistent with the Medium severity rating. All Google Chrome users running builds prior to 153.0.8010.36 are affected. There is no confirmed in-the-wild exploitation: the flaw is not in CISA KEV, EPSS estimates only a 0.2% probability of exploitation within 30 days (8th percentile), and the single public reference is a proof-of-concept issue in the Chromium tracker.

What to do: Update Google Chrome to version 153.0.8010.36 or later; since Chrome auto-updates, verify the installed version via Settings > About Chrome (chrome://settings/help). Until patched, avoid untrusted or unfamiliar web pages, and administrators should confirm fleet versions via endpoint management and restrict unpatched builds from accessing sensitive resources where feasible.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global install base; every build before 153.0.8010.36) — Chrome is the world's most widely deployed browser with an install base on the order of billions across desktop and mobile, and all installations remain exposed until they update to 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper state validation in Safebrowsing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-754
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.