CVE-2026-87606
massMissing Authorization in Google Chrome SiteIsolation Enables Isolation Bypass
CVE-2026-87606 is a missing authorization check (CWE-862) in the SiteIsolation component of Google Chrome that allows the browser's core cross-site containment defense to be bypassed. It is triggered by a crafted HTML page loaded in a browser whose renderer process has already been compromised, making this typically a second-stage issue chained with a separate renderer bug rather than a standalone attack. An attacker who exploits it defeats the process-level separation that site isolation enforces, weakening the browser's primary barrier against cross-origin data exposure and limiting the blast radius of renderer compromises. All Google Chrome versions prior to 153.0.8010.36 are affected; other Chromium-based browsers may inherit the issue, but only Chrome is named in the advisory. No public proof-of-concept is known, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation within 30 days; note the CVSS score is 8.1 (High) while Chromium rated the severity Medium because exploitation requires a pre-compromised renderer.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version at chrome://version. Because exploitation requires an already-compromised renderer process, treat this primarily as a chaining bug: prioritize remediation of renderer vulnerabilities and keep site isolation enabled rather than disabled. Ensure automatic browser updates are on so managed and personal fleets pick up the fixed release.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.