ZeroHour

CVE-2026-87632

mass

Cross-Site Scripting Bypass in SanitizerAPI Affects Google Chrome Prior to 153.0.8010.36

CVSS 3.1
4.3 medium
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-87632 is a cross-site scripting (XSS) flaw in the SanitizerAPI component of Google Chrome that allows a remote attacker to bypass the browser's web origin policy through a crafted HTML page. The flaw is triggered when a user visits an attacker-controlled or otherwise crafted HTML page, consistent with the CVSS vector's requirement for user interaction (UI:R). A successful exploit yields limited impact, primarily a low-severity confidentiality breach such as cross-origin information disclosure, with no integrity or availability impact per the CVSS score of 4.3. Users of Google Chrome on any platform prior to version 153.0.8010.36 are affected. As of publication there is no known public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, although the Chrome 153 release headlines mention a zero-day exploited in the wild that may be a separate flaw fixed in the same 230-fix release.

What to do: Update Google Chrome to version 153.0.8010.36 or later, which users can verify at chrome://settings/help; enterprise administrators should confirm managed endpoints have received the update via their browser management console. Until patched, exercise caution with unsolicited links and untrusted HTML pages. Given the low EPSS and absence of a public PoC, patching at normal patch-cycle cadence is reasonable, but apply it promptly alongside the Chrome 153 security release.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion Chrome users worldwide (browser's global install base) — Chrome is the world's most widely used desktop and mobile browser with a multi-billion-user install base, so essentially all Chrome users on versions before 153.0.8010.36 are plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cross-site scripting in SanitizerAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs