CVE-2026-87492
Google · Chrome
An incorrect authorization flaw in Google Chrome DevTools allows a remote attacker to achieve sandbox escape and execute arbitrary code via a malicious HTML page.
Executive summary
A critical vulnerability in Google Chrome allows remote attackers to bypass sandbox protections and execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
This vulnerability involves incorrect authorization within the DevTools component, which can be triggered by an unauthenticated remote attacker via a specially crafted HTML page. Successful exploitation enables the execution of arbitrary code outside of the browser sandbox.
Business impact
The ability to execute code outside the browser sandbox represents a critical security failure, as it effectively nullifies the primary defense mechanism protecting the underlying operating system. With a CVSS score of 9.6, this vulnerability could lead to total system compromise, unauthorized data exfiltration, or the installation of persistent malware, resulting in significant operational and reputational damage.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately across all managed endpoints to apply the security fix.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected network traffic originating from browser-related processes.
Compensating Controls: While no direct virtual patch exists for this specific logic flaw, ensure that all browser-based security policies are strictly enforced and consider utilizing endpoint detection and response (EDR) solutions to identify sandbox escape attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for full system control, organizations should prioritize the deployment of the Chrome update across their entire environment. Delaying this update exposes infrastructure to potential remote code execution threats that bypass standard browser-level security boundaries.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written