CVE-2026-87547
massIncorrect FileSystem Reference Resolution in Google Chrome May Allow Sandbox Escape
CVE-2026-87547 is an incorrect reference resolution flaw (CWE-706) in the FileSystem component of Google Chrome, where mishandled file system references could be abused by a remote attacker. Exploitation requires user interaction: the attacker must use social engineering to lure a user into opening a crafted HTML page. If successful, the attacker could potentially execute arbitrary code outside the browser's security sandbox, though Google's Chromium security team rates this flaw only Medium severity despite the critical CVSS 3.1 base score of 9.6. Users of Google Chrome versions prior to 153.0.8010.36 are affected. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later, verifying the installed version via chrome://settings/help or chrome://version. Because exploitation depends on social engineering, remind users to be cautious with unsolicited links and HTML pages. Enterprise administrators should confirm fleet-wide patch status through their browser update management tooling.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-706
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.