ZeroHour

CVE-2026-87577

PoC mass

Origin Policy Bypass in Google Chrome Isolated Component (Incorrect Authorization)

CVSS 3.1
4.3 medium
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-87577 is an incorrect authorization flaw (CWE-863) in the Isolated component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker triggers it by persuading a user to open a crafted HTML page, since the CVSS vector requires user interaction (UI:R). On success, the attacker bypasses web origin policy to gain access into a privileged page, with limited confidentiality impact (CVSS 4.3 Medium, C:L/I:N/A:N). Any user running Chrome prior to 153.0.8010.36 is affected. There is no evidence of in-the-wild exploitation — it is not in CISA KEV and EPSS assigns a 0.2% 30-day exploitation probability (9th percentile) — but one public proof-of-concept reference exists in the Chromium issue tracker.

What to do: Update Google Chrome to 153.0.8010.36 or later (verify via Settings > About Chrome, and enforce the fixed version through enterprise update management for managed fleets). The attack requires user interaction, so standard user-vigilance around untrusted web content applies; given Medium severity, absent KEV listing, and low EPSS, routine patching cadence is sufficient.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
masson the order of billions of Chrome users (Chrome's global active user base is publicly reported at ~3+ billion; all installations on versions prior to… — Chrome is the world's most widely deployed browser with a reported multi-billion active user base, so the affected population is best estimated at billions of users, tempered by auto-update roll-out of 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.