CVE-2026-87535
PoC massSafe Browsing information-loss access bypass in Google Chrome for Mac
CVE-2026-87535 is an information loss or omission flaw (CWE-221) in the Safe Browsing component of Google Chrome when running on macOS. A remote attacker triggers it by convincing a logged-in user to open a specially crafted HTML page, since user interaction is required. Successful exploitation lets the attacker bypass system access restrictions, an impact the CVSS vector scores as a high integrity loss with no confidentiality or availability impact. Only Mac users running Chrome versions prior to 153.0.8010.36 are affected. Exploitation has not been reported in the wild and the flaw is not in CISA's KEV; EPSS puts 30-day exploitation probability at roughly 0.2%, and one public issue/PoC reference exists on the Chromium issue tracker.
What to do: Update Chrome on macOS to version 153.0.8010.36 or later via chrome://settings/help or your update-management tool, and verify managed Mac fleets have received the update through MDM. Until patched, treat crafted HTML pages from untrusted sources with caution; there is no known configuration workaround.
| google chrome | Chrome on Mac (macOS) prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-221
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.