ZeroHour

CVE-2026-87582

mass

Confused Deputy Sandbox Escape in Google Chrome DataTransfer

CVSS 3.1
8.3 high
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-87582 is a confused deputy flaw (CWE-441) in the DataTransfer component of Google Chrome, rated Medium by Chromium but High (8.3) under CVSS 3.1. A remote attacker who has already compromised the Chrome renderer process can direct the browser to a crafted HTML page and abuse the flaw to execute arbitrary code outside the browser sandbox. This effectively provides a sandbox escape, escalating a renderer-level compromise into code execution beyond Chrome's security sandbox. All users of Google Chrome prior to 153.0.8010.36 are affected. No public proof of concept is known, the issue is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, indicating no known active exploitation.

What to do: Update Chrome to 153.0.8010.36 or later on all endpoints and verify the running version at chrome://settings/help; enterprise admins should confirm auto-update or roll the fix via managed browser update policies. Because exploitation requires an already-compromised renderer, treat this as a chaining issue and ensure other Chrome/Chromium renderer vulnerabilities are also promptly patched. No published workaround exists beyond updating.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
masson the order of billions of Chrome users/devices (Chrome's dominant global browser market share) — Chrome is the world's most widely used browser with an install base measured in the billions, so effectively all Chrome users running versions before 153.0.8010.36 are exposed until they update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Confused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-441
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.