ZeroHour

CVE-2026-87553

mass

Sandbox Escape via Improper Input Validation in Google Chrome SiteIsolation

CVSS 3.1
8.3 high
EPSS
<1%p30
Published
()
Modified
AI analysis

Google Chrome prior to 153.0.8010.36 contains an improper input validation flaw (CWE-20) in its SiteIsolation component. A remote attacker can trigger it by persuading a user to load a crafted HTML page, but exploitation also requires the attacker to have already compromised the Chrome renderer process, which is reflected in the high attack-complexity rating. If successful, the attacker breaks out of the Chrome sandbox and can potentially execute arbitrary code outside the sandbox, with high impact to confidentiality, integrity, and availability. Anyone running an affected Chrome build prior to 153.0.8010.36 is affected until they update. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days; note Chromium rates it Medium severity even though the CVSS 3.1 score is 8.3 (High).

What to do: Update Google Chrome to 153.0.8010.36 or later on all managed and personal devices and verify the fixed version via chrome://settings/help or your software inventory. Because the flaw requires an attacker to first compromise the renderer process, also promptly patch any renderer-process Chrome bugs and keep Site Isolation enabled as defense in depth. No in-the-wild exploitation is currently known, so routine patching cadence is sufficient for most organizations.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massseveral billion users (Chrome is the world's dominant browser with an installed base well over 1 billion) — Chrome's global browser market share of roughly two-thirds implies billions of active installations, nearly all of which were running pre-153 builds until auto-update completes; however, exploitation requires chaining with a prior renderer…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.