CVE-2026-87589
PoC massSiteIsolation Authorization Bypass in Google Chrome Before 153.0.8010.36
CVE-2026-87589 is an incorrect authorization flaw (CWE-863) in the SiteIsolation component of Google Chrome, affecting versions prior to 153.0.8010.36. To trigger it, an attacker must first compromise the Chrome renderer process (typically via another exploit), then use a crafted HTML page to bypass the access restrictions that SiteIsolation enforces. The result is a bypass of system access restrictions with integrity impact — the CVSS vector indicates no confidentiality or availability loss (C:N/I:H/A:N). All Chrome users running an affected version are exposed, though the attack requires a pre-existing renderer compromise, making it most useful as a link in a chained attack. Exploitation status is limited: one public proof-of-concept reference exists in the Chromium issue tracker, EPSS is low at 0.2% (7th percentile), and the issue is not in CISA KEV.
What to do: Update Google Chrome to 153.0.8010.36 or later; enterprise administrators should verify patched versions via chrome://settings/help or their endpoint management tooling. Because exploitation requires an already-compromised renderer, prioritize patching alongside any other open Chromium renderer vulnerabilities and treat this as a defense-in-depth fix rather than a standalone remote attack vector.
| google chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.