ZeroHour

CVE-2026-87644

mass

Sandbox Escape in Google Chrome on Windows via Incorrect Authorization in Views

CVSS 3.1
8.3 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-87644 is an incorrect authorization flaw (CWE-863) in the Views component of Google Chrome on Windows, present in versions prior to 153.0.8010.36. It is triggered by a crafted HTML page when a remote attacker has already compromised the Chrome renderer process and then uses social engineering to obtain the user interaction needed to abuse the authorization error. Successful exploitation lets the attacker execute arbitrary code outside the Chrome sandbox, giving code execution on the Windows host beyond the browser's normal process isolation. All Chrome users on Windows running affected versions are exposed; macOS and Linux installs are not named in the advisory. No public proof-of-concept or known exploitation exists, the flaw is not in CISA KEV, EPSS is low at 0.3%, and Google rated it Medium severity even though the published CVSS 3.1 score is 8.3 (High).

What to do: Update Google Chrome on Windows to 153.0.8010.36 or later; verify the running version at chrome://version or force the update via Settings > About Chrome. Because exploitation requires an already-compromised renderer plus user interaction, treat this patch as defense-in-depth and alert users to be wary of unexpected browser prompts or permission requests after visiting unfamiliar pages. There is no known workaround beyond updating.

Affected
Google ChromeWindows versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions of Windows Chrome installations (Chrome serves 3B+ users; most auto-update within days, shrinking the unpatched window) — Chrome's global installed base exceeds 3 billion users and Windows is the dominant desktop platform for Chrome, but the short-lived unpatched population before auto-update lands is the realistic exposure set.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.