CVE-2026-87618
massSandbox escape via incorrect reference resolution in Google Chrome on Windows
CVE-2026-87618 is an incorrect reference resolution flaw (CWE-706) in the Storage component of Google Chrome on Windows. It is triggered when a remote attacker, who has already compromised the browser's renderer process, gets the user to load a crafted HTML page. Successful exploitation allows the attacker to potentially execute arbitrary code outside the Chrome sandbox, effectively a sandbox escape; Chromium rates the flaw Low severity precisely because it requires that pre-existing renderer compromise. Anyone running Google Chrome on Windows prior to version 153.0.8010.36 is affected. No public proof-of-concept or in-the-wild exploitation is currently known, the flaw is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at just 0.2%.
What to do: Update Google Chrome on Windows to 153.0.8010.36 or later; enterprises should verify patched browser versions via their update-management or endpoint inventories and keep managed-browser auto-update policies enabled. Treat this as a chain component: it matters most when combined with a renderer exploit, so patch promptly but prioritize higher-severity Chrome renderer bugs alongside it.
| Google Chrome (Windows) | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-706
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.