ZeroHour

CVE-2026-87606

mass

Missing Authorization in Google Chrome SiteIsolation Enables Isolation Bypass

CVSS 3.1
8.1 high
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-87606 is a missing authorization check (CWE-862) in the SiteIsolation component of Google Chrome that allows the browser's core cross-site containment defense to be bypassed. It is triggered by a crafted HTML page loaded in a browser whose renderer process has already been compromised, making this typically a second-stage issue chained with a separate renderer bug rather than a standalone attack. An attacker who exploits it defeats the process-level separation that site isolation enforces, weakening the browser's primary barrier against cross-origin data exposure and limiting the blast radius of renderer compromises. All Google Chrome versions prior to 153.0.8010.36 are affected; other Chromium-based browsers may inherit the issue, but only Chrome is named in the advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days; note the CVSS score is 8.1 (High) while Chromium rated the severity Medium because exploitation requires a pre-compromised renderer.

What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version at chrome://version. Because exploitation requires an already-compromised renderer process, treat this primarily as a chaining bug: prioritize remediation of renderer vulnerabilities and keep site isolation enabled rather than disabled. Ensure automatic browser updates are on so managed and personal fleets pick up the fixed release.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of installations (Chrome's reported global user base of 3+ billion; every build before 153.0.8010.36) — Chrome holds roughly two-thirds of global desktop browser market share with a publicly reported user base exceeding three billion, and the flaw applies to all releases prior to 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.