ZeroHour

CVE-2026-87570

mass

Site Isolation Bypass via Incorrect Authorization in Google Chrome

CVSS 3.1
8.8 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2026-87570 is an incorrect authorization flaw (CWE-863) in the SiteIsolation component of Google Chrome, fixed in Chrome 153.0.8010.36. Exploitation requires a chain: a remote attacker must first compromise the Chrome renderer process, then use social engineering to get the user to interact with a crafted file, after which the attacker can bypass site isolation. Bypassing site isolation undermines Chrome's core defense of confining each website to its own process, so an attacker already controlling a renderer could gain access to content from origins other than the one they compromised. All users running Chrome builds earlier than 153.0.8010.36 are affected. No public proof-of-concept, in-the-wild exploitation, or KEV listing is known; EPSS assigns a 0.2% 30-day exploitation probability (6th percentile), and Google rated the issue Medium in Chromium even though the CVSS 3.1 base score is 8.8 (High).

What to do: Update Chrome to 153.0.8010.36 or later on all endpoints (verifiable via Help > About Chrome), and for managed fleets confirm the update has propagated through your browser management policy. Because exploitation requires an already-compromised renderer plus user interaction with a crafted file, keep Chromium-based applications patched promptly and remind users to be cautious about opening files prompted by unfamiliar web content.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of users worldwide; effectively every Chrome installation running a build before 153.0.8010.36 — Chrome is the dominant browser with an estimated multi-billion active user base (roughly 60-65% of desktop browser usage per public market-share data), and each un-updated install prior to 153.0.8010.36 counts as affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted file. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.