CVE-2026-87471

Google · Chrome

A flaw in Google Chrome ServiceWorker logic allows a remote attacker who has compromised the renderer process to bypass site isolation protections using a specially crafted HTML page.

Executive summary

A critical authorization vulnerability in Google Chrome allows remote attackers to bypass site isolation, potentially leading to unauthorized cross-site data access.

Vulnerability

This vulnerability involves incorrect authorization within the ServiceWorker component. An attacker who has already achieved code execution within the renderer process can leverage this flaw to bypass site isolation, effectively violating the security boundaries between different web origins.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to cross-site data, which can lead to the exposure of sensitive user information or session tokens. With a CVSS score of 8.1, this high-severity flaw poses a significant risk to data confidentiality and integrity, particularly in enterprise environments where users handle sensitive corporate or personal data.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later to incorporate the necessary authorization fixes.

Proactive Monitoring: Monitor endpoint security logs for signs of anomalous browser behavior or unexpected ServiceWorker activity that may indicate an attempt to bypass site isolation.

Compensating Controls: While browser-level patches are the only definitive fix, ensure that endpoint detection and response (EDR) solutions are active to identify and block the initial renderer process compromise required to trigger this flaw.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for cross-site data compromise, administrators should prioritize the deployment of the 153.0.8010.36 update across all workstations. Ensuring that browsers remain on the latest stable channel is a critical defense against this and similar sandbox-escape vulnerabilities.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.1 (3.1)
  4. Analyst report written

Sources