CVE-2026-87487
Google · Chrome
A missing authorization flaw in the Google Chrome FileSystem allows a remote attacker to achieve sandbox escape and arbitrary code execution through a compromised renderer process and social engineering.
Executive summary
A critical authorization vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox, posing a severe risk to system integrity.
Vulnerability
This vulnerability involves a missing authorization check within the FileSystem component, which can be triggered by an unauthenticated remote attacker using a crafted HTML page to escape the browser sandbox after compromising the renderer process.
Business impact
The potential for arbitrary code execution outside the browser sandbox represents a significant threat to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and the deployment of persistent malware on the host machine. Given the CVSS score of 8.3, this issue is classified as high severity and requires immediate attention to prevent potential lateral movement within the network.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately across all managed endpoints.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected file system modifications initiated by the browser process.
Compensating Controls: Ensure that browser-based security policies, such as site isolation and strict sandboxing, are enforced via Group Policy or mobile device management solutions to limit the impact of potential renderer compromises.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with its potential for sandbox escape, necessitates an urgent patching cycle. Security teams should prioritize the deployment of the update across the enterprise environment to mitigate the risk of remote code execution. Failure to patch may expose workstations to advanced persistent threats that leverage browser-based entry points for deeper system access.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.3 (3.1)
- Analyst report written