CVE-2026-87582
massConfused Deputy Sandbox Escape in Google Chrome DataTransfer
CVE-2026-87582 is a confused deputy flaw (CWE-441) in the DataTransfer component of Google Chrome, rated Medium by Chromium but High (8.3) under CVSS 3.1. A remote attacker who has already compromised the Chrome renderer process can direct the browser to a crafted HTML page and abuse the flaw to execute arbitrary code outside the browser sandbox. This effectively provides a sandbox escape, escalating a renderer-level compromise into code execution beyond Chrome's security sandbox. All users of Google Chrome prior to 153.0.8010.36 are affected. No public proof of concept is known, the issue is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, indicating no known active exploitation.
What to do: Update Chrome to 153.0.8010.36 or later on all endpoints and verify the running version at chrome://settings/help; enterprise admins should confirm auto-update or roll the fix via managed browser update policies. Because exploitation requires an already-compromised renderer, treat this as a chaining issue and ensure other Chrome/Chromium renderer vulnerabilities are also promptly patched. No published workaround exists beyond updating.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-441
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.