CVE-2026-87509
Google · Chrome
A vulnerability in the Google Chrome Updater for Windows allows a local attacker to execute arbitrary code outside the sandbox via a local program due to incorrect authorization.
Executive summary
A critical authorization flaw in the Google Chrome Updater for Windows may allow local attackers to achieve arbitrary code execution outside of the browser sandbox.
Vulnerability
This vulnerability, categorized as CWE-863 (Incorrect Authorization), exists within the update mechanism of the browser. It allows an attacker with local access to the system to bypass security boundaries and execute arbitrary code, despite the browser's internal sandbox protections.
Business impact
While the Chromium project labels this as Low severity, the CVSS score of 8.1 indicates a High severity risk due to the potential for total system compromise. Successful exploitation could allow an attacker to gain elevated control over the host machine, leading to unauthorized data access, persistence, or lateral movement within the corporate network.
Remediation
Immediate Action: Update Google Chrome for Windows to version 153.0.8010.36 or later immediately to address the authorization flaw.
Proactive Monitoring: Monitor system logs for unauthorized attempts to invoke the browser update process or unexpected execution of local programs that interact with browser directory structures.
Compensating Controls: Ensure that local users operate with the principle of least privilege, as this vulnerability requires local access to the host machine to trigger the exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk posed by sandbox escapes necessitates prompt patching of the browser software. IT administrators should prioritize the deployment of version 153.0.8010.36 across all Windows-based endpoints to eliminate this local execution vector. Consistent browser hygiene remains a foundational requirement for securing client-side environments.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written