CVE-2026-87537
massMissing Authorization in Google Chrome Extensions Enables Sandbox Escape
CVE-2026-87537 is a missing-authorization flaw (CWE-862) in the Extensions component of Google Chrome, fixed in version 153.0.8010.36. To exploit it, a remote attacker must first compromise a Chrome renderer process (for example via a separate renderer-level bug or malicious web content) and then send crafted network traffic that the Extensions component fails to properly authorize. A successful exploit potentially allows arbitrary code execution outside the Chrome sandbox, giving the attacker access with high confidentiality, integrity, and availability impact on the host. All Google Chrome installations on versions prior to 153.0.8010.36 are affected; the prerequisite renderer compromise raises the attack complexity, which is why Chromium rates it Medium despite the CVSS 8.1 base score. There is currently no known public proof of concept, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at a low 0.2%.
What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, and verify fleet-wide compliance via chrome://version, MDM, or Chrome Browser Cloud Management reports. Because exploitation requires an already-compromised renderer, also promptly apply fixes for renderer-level Chrome flaws and minimize unnecessary extensions to shrink the attack surface. No workarounds are described in the available data, so patching is the primary mitigation.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.