CVE-2026-87644
massSandbox Escape in Google Chrome on Windows via Incorrect Authorization in Views
CVE-2026-87644 is an incorrect authorization flaw (CWE-863) in the Views component of Google Chrome on Windows, present in versions prior to 153.0.8010.36. It is triggered by a crafted HTML page when a remote attacker has already compromised the Chrome renderer process and then uses social engineering to obtain the user interaction needed to abuse the authorization error. Successful exploitation lets the attacker execute arbitrary code outside the Chrome sandbox, giving code execution on the Windows host beyond the browser's normal process isolation. All Chrome users on Windows running affected versions are exposed; macOS and Linux installs are not named in the advisory. No public proof-of-concept or known exploitation exists, the flaw is not in CISA KEV, EPSS is low at 0.3%, and Google rated it Medium severity even though the published CVSS 3.1 score is 8.3 (High).
What to do: Update Google Chrome on Windows to 153.0.8010.36 or later; verify the running version at chrome://version or force the update via Settings > About Chrome. Because exploitation requires an already-compromised renderer plus user interaction, treat this patch as defense-in-depth and alert users to be wary of unexpected browser prompts or permission requests after visiting unfamiliar pages. There is no known workaround beyond updating.
| Google Chrome | Windows versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.