ZeroHour

CVE-2026-87535

PoC mass

Safe Browsing information-loss access bypass in Google Chrome for Mac

CVSS 3.1
6.5 medium
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-87535 is an information loss or omission flaw (CWE-221) in the Safe Browsing component of Google Chrome when running on macOS. A remote attacker triggers it by convincing a logged-in user to open a specially crafted HTML page, since user interaction is required. Successful exploitation lets the attacker bypass system access restrictions, an impact the CVSS vector scores as a high integrity loss with no confidentiality or availability impact. Only Mac users running Chrome versions prior to 153.0.8010.36 are affected. Exploitation has not been reported in the wild and the flaw is not in CISA's KEV; EPSS puts 30-day exploitation probability at roughly 0.2%, and one public issue/PoC reference exists on the Chromium issue tracker.

What to do: Update Chrome on macOS to version 153.0.8010.36 or later via chrome://settings/help or your update-management tool, and verify managed Mac fleets have received the update through MDM. Until patched, treat crafted HTML pages from untrusted sources with caution; there is no known configuration workaround.

Affected
google chromeChrome on Mac (macOS) prior to 153.0.8010.36
Estimated exposure
masswell over 100 million users (Chrome-on-macOS install base) — Chrome has billions of users worldwide and macOS holds a double-digit share of desktop browser installs, so the affected Mac subset plausibly exceeds 100 million users; the exact patched-versus-unpatched split is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-221
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.