CVE-2026-87580
PoC massIncorrect Authorization in Google Chrome WebAppInstalls Bypasses Site Isolation
CVE-2026-87580 is an incorrect authorization flaw (CWE-863) in the WebAppInstalls component of Google Chrome that allows the browser's site isolation boundary to be bypassed. Triggering it requires two steps: an attacker must first compromise the renderer process, then use social engineering to get the user to interact with a crafted HTML page. The payoff is a bypass of site isolation, and the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) rates the impact as high on integrity with no direct confidentiality or availability loss. Everyone running Google Chrome prior to 153.0.8010.36 is affected. There is no evidence of exploitation in the wild (not in CISA KEV, EPSS just 0.2%), and only one public issue-tracker reference (a PoC/bug reference at issues.chromium.org) is available.
What to do: Update Google Chrome to 153.0.8010.36 or later — verify via chrome://settings/help or rely on auto-update, and refresh enterprise-managed browsers through your update channel. Because exploitation requires an already-compromised renderer plus user interaction, treat this as a patch-and-hygiene issue: no workaround beyond upgrading is documented, so prioritize updating and remind users to be wary of prompts and install flows on untrusted pages.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.