ZeroHour

CVE-2026-87537

mass

Missing Authorization in Google Chrome Extensions Enables Sandbox Escape

CVSS 3.1
8.1 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-87537 is a missing-authorization flaw (CWE-862) in the Extensions component of Google Chrome, fixed in version 153.0.8010.36. To exploit it, a remote attacker must first compromise a Chrome renderer process (for example via a separate renderer-level bug or malicious web content) and then send crafted network traffic that the Extensions component fails to properly authorize. A successful exploit potentially allows arbitrary code execution outside the Chrome sandbox, giving the attacker access with high confidentiality, integrity, and availability impact on the host. All Google Chrome installations on versions prior to 153.0.8010.36 are affected; the prerequisite renderer compromise raises the attack complexity, which is why Chromium rates it Medium despite the CVSS 8.1 base score. There is currently no known public proof of concept, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at a low 0.2%.

What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, and verify fleet-wide compliance via chrome://version, MDM, or Chrome Browser Cloud Management reports. Because exploitation requires an already-compromised renderer, also promptly apply fixes for renderer-level Chrome flaws and minimize unnecessary extensions to shrink the attack surface. No workarounds are described in the available data, so patching is the primary mitigation.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome's global installed base, roughly 65% browser market share) — Chrome is the world's dominant browser with an estimated multi-billion-user installed base, and every endpoint running a build earlier than 153.0.8010.36 is exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.