ZeroHour

CVE-2026-87547

mass

Incorrect FileSystem Reference Resolution in Google Chrome May Allow Sandbox Escape

CVSS 3.1
9.6 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-87547 is an incorrect reference resolution flaw (CWE-706) in the FileSystem component of Google Chrome, where mishandled file system references could be abused by a remote attacker. Exploitation requires user interaction: the attacker must use social engineering to lure a user into opening a crafted HTML page. If successful, the attacker could potentially execute arbitrary code outside the browser's security sandbox, though Google's Chromium security team rates this flaw only Medium severity despite the critical CVSS 3.1 base score of 9.6. Users of Google Chrome versions prior to 153.0.8010.36 are affected. There is currently no known exploitation: no public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later, verifying the installed version via chrome://settings/help or chrome://version. Because exploitation depends on social engineering, remind users to be cautious with unsolicited links and HTML pages. Enterprise administrators should confirm fleet-wide patch status through their browser update management tooling.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
masspotentially billions of users (Chrome has an estimated 3+ billion global users) — Chrome is the world's dominant desktop browser with an estimated 3+ billion users, and the flaw affects every version before the 153.0.8010.36 fix release, so the population of possibly affected installs is on the order of billions, though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect reference resolution in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.