ZeroHour

CVE-2026-87589

PoC mass

SiteIsolation Authorization Bypass in Google Chrome Before 153.0.8010.36

CVSS 3.1
6.5 medium
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-87589 is an incorrect authorization flaw (CWE-863) in the SiteIsolation component of Google Chrome, affecting versions prior to 153.0.8010.36. To trigger it, an attacker must first compromise the Chrome renderer process (typically via another exploit), then use a crafted HTML page to bypass the access restrictions that SiteIsolation enforces. The result is a bypass of system access restrictions with integrity impact — the CVSS vector indicates no confidentiality or availability loss (C:N/I:H/A:N). All Chrome users running an affected version are exposed, though the attack requires a pre-existing renderer compromise, making it most useful as a link in a chained attack. Exploitation status is limited: one public proof-of-concept reference exists in the Chromium issue tracker, EPSS is low at 0.2% (7th percentile), and the issue is not in CISA KEV.

What to do: Update Google Chrome to 153.0.8010.36 or later; enterprise administrators should verify patched versions via chrome://settings/help or their endpoint management tooling. Because exploitation requires an already-compromised renderer, prioritize patching alongside any other open Chromium renderer vulnerabilities and treat this as a defense-in-depth fix rather than a standalone remote attack vector.

Affected
google chromeAll versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome's global install base, ~3+ billion) — Chrome is the world's most-used browser with roughly 60-65% market share and an install base on the order of billions of users, so virtually every desktop fleet has affected versions until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.