CVE-2026-87530
Google · Chrome
A local uncontrolled search path element vulnerability in the Google Chrome CredentialProvider on Windows allows attackers to execute arbitrary code outside the browser sandbox.
Executive summary
A high-severity local code execution vulnerability in Google Chrome on Windows poses a significant risk to system integrity and security.
Vulnerability
This vulnerability is caused by an uncontrolled search path element (CWE-427) within the CredentialProvider component. It allows an unauthenticated local attacker to bypass sandbox protections and execute arbitrary code via a malicious local program.
Business impact
The ability to execute code outside the Chrome sandbox represents a critical failure of the browser security model. If exploited, an attacker could gain elevated privileges on the host operating system, leading to full system compromise, data exfiltration, or the installation of persistent malware. Given the CVSS score of 8.1, this vulnerability is categorized as high risk, necessitating prioritized patching for all Windows-based workstations.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to resolve the vulnerable search path logic.
Proactive Monitoring: Monitor endpoint security logs for unauthorized binary execution or unusual process creation originating from the Chrome CredentialProvider component.
Compensating Controls: Ensure robust endpoint protection platforms are active and configured to block the execution of unsigned or suspicious executables in application directories.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk of sandbox escape makes this vulnerability a priority for remediation on all Windows systems running Google Chrome. Administrators should verify that the update to version 153.0.8010.36 is deployed across the enterprise environment as soon as possible to mitigate the risk of local privilege escalation and system compromise.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written