CVE-2026-87505

Google · Chrome

An incorrect authorization vulnerability in the Google Chrome FileSystem component allows remote attackers to bypass site isolation using a crafted PDF file.

Executive summary

A high-severity authorization vulnerability in Google Chrome allows remote attackers to bypass site isolation protections via malicious PDF files.

Vulnerability

This flaw is caused by incorrect authorization logic within the FileSystem component. A remote, unauthenticated attacker can exploit this via a crafted PDF to bypass site isolation if they have already compromised the renderer process.

Business impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive data and potential cross-site information disclosure. Given the CVSS score of 8.1, the risk is classified as High, as it undermines core browser security boundaries designed to protect user sessions and private information from malicious websites.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary authorization fixes.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or repeated crashes involving the renderer process.

Compensating Controls: While no direct virtual patch exists, ensuring that users are restricted from downloading or opening untrusted PDF files from unknown sources can reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability represents a critical failure in the site isolation mechanism of the Google Chrome browser. Security teams must prioritize the deployment of the 153.0.8010.36 update across all managed workstations to ensure that the authorization bypass is remediated and that users are protected from potential cross-site data theft.

More Google CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.1 (3.1)
  4. Analyst report written

Sources