CVE-2026-87570
massSite Isolation Bypass via Incorrect Authorization in Google Chrome
CVE-2026-87570 is an incorrect authorization flaw (CWE-863) in the SiteIsolation component of Google Chrome, fixed in Chrome 153.0.8010.36. Exploitation requires a chain: a remote attacker must first compromise the Chrome renderer process, then use social engineering to get the user to interact with a crafted file, after which the attacker can bypass site isolation. Bypassing site isolation undermines Chrome's core defense of confining each website to its own process, so an attacker already controlling a renderer could gain access to content from origins other than the one they compromised. All users running Chrome builds earlier than 153.0.8010.36 are affected. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known; EPSS assigns a 0.2% 30-day exploitation probability (6th percentile), and Google rated the issue Medium in Chromium even though the CVSS 3.1 base score is 8.8 (High).
What to do: Update Chrome to 153.0.8010.36 or later on all endpoints (verifiable via Help > About Chrome), and for managed fleets confirm the update has propagated through your browser management policy. Because exploitation requires an already-compromised renderer plus user interaction with a crafted file, keep Chromium-based applications patched promptly and remind users to be cautious about opening files prompted by unfamiliar web content.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.