Cross-Site Scripting Bypass in SanitizerAPI Affects Google Chrome Prior to 153.0.8010.36
AI analysis
CVE-2026-87632 is a cross-site scripting (XSS) flaw in the SanitizerAPI component of Google Chrome that allows a remote attacker to bypass the browser's web origin policy through a crafted HTML page. The flaw is triggered when a user visits an attacker-controlled or otherwise crafted HTML page, consistent with the CVSS vector's requirement for user interaction (UI:R). A successful exploit yields limited impact, primarily a low-severity confidentiality breach such as cross-origin information disclosure, with no integrity or availability impact per the CVSS score of 4.3. Users of Google Chrome on any platform prior to version 153.0.8010.36 are affected. As of publication there is no known public proof-of-concept, the CVE is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, although the Chrome 153 release headlines mention a zero-day exploited in the wild that may be a separate flaw fixed in the same 230-fix release.
What to do: Update Google Chrome to version 153.0.8010.36 or later, which users can verify at chrome://settings/help; enterprise administrators should confirm managed endpoints have received the update via their browser management console. Until patched, exercise caution with unsolicited links and untrusted HTML pages. Given the low EPSS and absence of a public PoC, patching at normal patch-cycle cadence is reasonable, but apply it promptly alongside the Chrome 153 security release.
Affected
| google chrome | all versions prior to 153.0.8010.36 |
Estimated exposure
mass≈3+ billion Chrome users worldwide (browser's global install base) — Chrome is the world's most widely used desktop and mobile browser with a multi-billion-user install base, so essentially all Chrome users on versions before 153.0.8010.36 are plausibly affected.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.