CVE-2026-87499

Google · Chrome

A flaw in Google Chrome's Network component allows a remote attacker who has compromised the renderer process to bypass site isolation using a crafted HTML page.

Executive summary

A high-severity authorization vulnerability in Google Chrome allows remote attackers to bypass site isolation protections, potentially leading to unauthorized data access.

Vulnerability

This issue involves incorrect authorization within the Network component of the browser, which can be exploited by an unauthenticated remote attacker who has already achieved code execution within the renderer process. By leveraging a specially crafted HTML page, the attacker can circumvent site isolation boundaries to access sensitive information.

Business impact

The ability to bypass site isolation represents a significant security failure, as it breaks the fundamental security model that prevents different websites from accessing each other's data. With a CVSS score of 8.1, this vulnerability carries a high risk of data compromise, potentially allowing an attacker to steal user credentials, session tokens, or sensitive cross-site information, leading to severe reputational damage and regulatory non-compliance.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary authorization fixes.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or attempts to execute unauthorized scripts within the browser process.

Compensating Controls: Ensure that browser-based security policies are strictly enforced and maintain updated endpoint protection software to detect and block malicious renderer process activity.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of site isolation for browser security, organizations should treat this update with high priority. Users and administrators must ensure that all instances of Google Chrome are updated to the patched version to mitigate the risk of cross-site data theft.

More Google CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.1 (3.1)
  4. Analyst report written

Sources