CVE-2026-87510

Google · Chrome

Google Chrome contains a vulnerability in the FileAPI caused by improper input validation, allowing a remote attacker to achieve sandbox escape and execute arbitrary code.

Executive summary

A critical vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox, posing a severe risk to system integrity.

Vulnerability

This flaw involves improper input validation within the FileAPI component. An unauthenticated attacker can exploit this via a crafted HTML page to escape the renderer sandbox and execute code on the host system.

Business impact

Successful exploitation grants an attacker the ability to bypass browser security boundaries, leading to full system compromise or unauthorized access to sensitive user data. While the CVSS score of 8.3 reflects a high severity, the potential for arbitrary code execution outside the sandbox makes this a critical priority for all environments utilizing Chrome.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns originating from the browser or unauthorized file system interactions.

Compensating Controls: Ensure that the browser is running with the latest security patches and leverage endpoint detection and response (EDR) tools to identify and block suspicious child processes spawned by browser components.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

This vulnerability represents a significant security risk due to the potential for sandbox escape and subsequent arbitrary code execution. Organizations must prioritize the deployment of the 153.0.8010.36 update across all desktop environments to mitigate the possibility of host-level compromise.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources