ZeroHour

CVE-2026-87580

PoC mass

Incorrect Authorization in Google Chrome WebAppInstalls Bypasses Site Isolation

CVSS 3.1
6.5 medium
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-87580 is an incorrect authorization flaw (CWE-863) in the WebAppInstalls component of Google Chrome that allows the browser's site isolation boundary to be bypassed. Triggering it requires two steps: an attacker must first compromise the renderer process, then use social engineering to get the user to interact with a crafted HTML page. The payoff is a bypass of site isolation, and the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) rates the impact as high on integrity with no direct confidentiality or availability loss. Everyone running Google Chrome prior to 153.0.8010.36 is affected. There is no evidence of exploitation in the wild (not in CISA KEV, EPSS just 0.2%), and only one public issue-tracker reference (a PoC/bug reference at issues.chromium.org) is available.

What to do: Update Google Chrome to 153.0.8010.36 or later — verify via chrome://settings/help or rely on auto-update, and refresh enterprise-managed browsers through your update channel. Because exploitation requires an already-compromised renderer plus user interaction, treat this as a patch-and-hygiene issue: no workaround beyond upgrading is documented, so prioritize updating and remind users to be wary of prompts and install flows on untrusted pages.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome's global install base is estimated at 3+ billion) — Chrome is the world's dominant browser with roughly 65% market share and a multi-billion install base, so effectively all users on versions before 153.0.8010.36 are potentially in scope — an order-of-magnitude estimate, not a per-CVE count.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in WebAppInstalls in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.