CVE-2026-87570

Google · Chrome

An incorrect authorization vulnerability in Google Chrome Site Isolation allows remote attackers to bypass security boundaries through a crafted file and social engineering.

Executive summary

A critical authorization flaw in Google Chrome allows remote attackers to bypass site isolation protections, potentially leading to full system compromise via social engineering.

Vulnerability

This vulnerability involves incorrect authorization within the Site Isolation component (CWE-863). An unauthenticated remote attacker can exploit this by compromising the renderer process and utilizing social engineering to manipulate a crafted file, effectively bypassing browser security boundaries.

Business impact

The exploitation of this vulnerability can result in unauthorized access to sensitive user data, cross-site scripting attacks, or full system compromise depending on the user environment. With a CVSS score of 8.8, this flaw represents a significant risk to organizational security, as it undermines the core isolation mechanisms intended to protect users from malicious web content.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected file downloads that correlate with potential social engineering attempts.

Compensating Controls: Implement robust email filtering and user awareness training to mitigate the social engineering component required to trigger this vulnerability.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity of this authorization bypass, organizations must prioritize the deployment of the latest Chrome update across all managed endpoints. Failure to patch these browsers leaves users susceptible to sophisticated attacks that leverage the trust inherent in the rendering process, potentially leading to unauthorized data exfiltration or system-level exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources