CVE-2026-87537

Google · Chrome

A missing authorization flaw in Google Chrome Extensions allows a remote attacker who has compromised the renderer process to potentially execute arbitrary code outside the sandbox.

Executive summary

A high-severity missing authorization vulnerability in Google Chrome could allow a remote attacker to achieve arbitrary code execution by exploiting the browser extension sandbox.

Vulnerability

This vulnerability, categorized under CWE-862, involves missing authorization checks within the browser extension framework. A remote attacker capable of compromising the renderer process can leverage crafted network traffic to bypass sandbox restrictions and execute arbitrary code.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it grants an attacker the ability to execute unauthorized commands on the host system. With a CVSS score of 8.1, this vulnerability is classified as high severity, indicating that successful exploitation could lead to full system compromise, data exfiltration, or the deployment of persistent malware.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Security teams should monitor endpoint security logs for suspicious extension activity or unauthorized process spawning originating from the Chrome browser.

Compensating Controls: Ensure that browser-based security policies, such as enterprise-managed extension allowlists, are enforced to limit the potential attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of sandbox escape vulnerabilities, immediate remediation is required. Organizations should prioritize updating all Google Chrome installations across their fleet to the fixed version to neutralize the threat of arbitrary code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.1 (3.1)
  4. Analyst report written

Sources