CVE-2026-87582

Google · Chrome

A confused deputy vulnerability exists in the DataTransfer component of Google Chrome, allowing a remote attacker to achieve sandbox escape and arbitrary code execution via a crafted HTML page.

Executive summary

A high-severity sandbox escape vulnerability in Google Chrome allows remote attackers to execute arbitrary code on the underlying host system.

Vulnerability

This vulnerability is a confused deputy flaw (CWE-441) within the DataTransfer component that enables a remote, unauthenticated attacker to bypass the browser sandbox. By leveraging a compromised renderer process through a malicious HTML page, an attacker can execute arbitrary code outside the established security boundaries.

Business impact

Successful exploitation of this flaw poses a significant risk to organizational endpoints, as it allows for full sandbox escape and potential remote code execution. Given the CVSS score of 8.3, this vulnerability represents a high risk for data theft, malware installation, and complete system compromise. Organizations relying on Chrome for daily operations are at risk of significant security breaches if this flaw is weaponized against their user base.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint detection and response logs for unusual process execution patterns originating from the browser or attempts to access restricted system resources.

Compensating Controls: Ensure that the browser is running with the latest security updates and consider using enterprise policies to restrict high-risk features if a patch cannot be deployed globally.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates rapid deployment of the provided security update. Administrators should prioritize patching all browser installations across the enterprise to eliminate the risk of sandbox escape and remote code execution, as the potential for total system compromise is substantial.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources