CVE-2026-87553
massSandbox Escape via Improper Input Validation in Google Chrome SiteIsolation
Google Chrome prior to 153.0.8010.36 contains an improper input validation flaw (CWE-20) in its SiteIsolation component. A remote attacker can trigger it by persuading a user to load a crafted HTML page, but exploitation also requires the attacker to have already compromised the Chrome renderer process, which is reflected in the high attack-complexity rating. If successful, the attacker breaks out of the Chrome sandbox and can potentially execute arbitrary code outside the sandbox, with high impact to confidentiality, integrity, and availability. Anyone running an affected Chrome build prior to 153.0.8010.36 is affected until they update. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days; note Chromium rates it Medium severity even though the CVSS 3.1 score is 8.3 (High).
What to do: Update Google Chrome to 153.0.8010.36 or later on all managed and personal devices and verify the fixed version via chrome://settings/help or your software inventory. Because the flaw requires an attacker to first compromise the renderer process, also promptly patch any renderer-process Chrome bugs and keep Site Isolation enabled as defense in depth. No in-the-wild exploitation is currently known, so routine patching cadence is sufficient for most organizations.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.