CVE-2026-87553

Google · Chrome

A vulnerability in Google Chrome's SiteIsolation feature allows a remote attacker who has compromised the renderer process to escape the sandbox and execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity sandbox escape vulnerability in Google Chrome could allow remote attackers to execute arbitrary code on the underlying host system.

Vulnerability

This flaw involves improper input validation within the SiteIsolation component. It allows an unauthenticated remote attacker, who has already gained control of the renderer process, to break out of the sandbox environment and execute arbitrary code.

Business impact

The ability to escape the browser sandbox and execute arbitrary code represents a severe threat to workstation integrity. Successful exploitation could lead to total system compromise, unauthorized data exfiltration, and lateral movement within the corporate network. With a CVSS score of 8.3, this vulnerability poses a significant risk that warrants immediate patching across all managed endpoints.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary input validation fixes.

Proactive Monitoring: Review system and application logs for unusual process execution patterns or unexpected spikes in resource usage that may indicate a sandbox escape attempt.

Compensating Controls: Ensure that Endpoint Detection and Response (EDR) solutions are active and configured to detect anomalous child process creation originating from the browser's renderer processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of sandbox escape vulnerabilities in web browsers, organizations should treat this update with high urgency. Administrators must deploy the latest version of Google Chrome to all users to close this security gap and prevent potential remote code execution attacks.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources