CVE-2026-87577
PoC massOrigin Policy Bypass in Google Chrome Isolated Component (Incorrect Authorization)
CVE-2026-87577 is an incorrect authorization flaw (CWE-863) in the Isolated component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker triggers it by persuading a user to open a crafted HTML page, since the CVSS vector requires user interaction (UI:R). On success, the attacker bypasses web origin policy to gain access into a privileged page, with limited confidentiality impact (CVSS 4.3 Medium, C:L/I:N/A:N). Any user running Chrome prior to 153.0.8010.36 is affected. There is no evidence of in-the-wild exploitation — it is not in CISA KEV and EPSS assigns a 0.2% 30-day exploitation probability (9th percentile) — but one public proof-of-concept reference exists in the Chromium issue tracker.
What to do: Update Google Chrome to 153.0.8010.36 or later (verify via Settings > About Chrome, and enforce the fixed version through enterprise update management for managed fleets). The attack requires user interaction, so standard user-vigilance around untrusted web content applies; given Medium severity, absent KEV listing, and low EPSS, routine patching cadence is sufficient.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.