CVE-2026-87537
Google · Chrome
A missing authorization flaw in Google Chrome Extensions allows a remote attacker who has compromised the renderer process to potentially execute arbitrary code outside the sandbox.
Executive summary
A high-severity missing authorization vulnerability in Google Chrome could allow a remote attacker to achieve arbitrary code execution by exploiting the browser extension sandbox.
Vulnerability
This vulnerability, categorized under CWE-862, involves missing authorization checks within the browser extension framework. A remote attacker capable of compromising the renderer process can leverage crafted network traffic to bypass sandbox restrictions and execute arbitrary code.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it grants an attacker the ability to execute unauthorized commands on the host system. With a CVSS score of 8.1, this vulnerability is classified as high severity, indicating that successful exploitation could lead to full system compromise, data exfiltration, or the deployment of persistent malware.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Security teams should monitor endpoint security logs for suspicious extension activity or unauthorized process spawning originating from the Chrome browser.
Compensating Controls: Ensure that browser-based security policies, such as enterprise-managed extension allowlists, are enforced to limit the potential attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of sandbox escape vulnerabilities, immediate remediation is required. Organizations should prioritize updating all Google Chrome installations across their fleet to the fixed version to neutralize the threat of arbitrary code execution.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written