CVE-2026-87479: Google Google Chrome vulnerability
Published Sep 9, 2026
·Updated
Insufficient policy enforcement in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
1 affected component
Google Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker achieve before this issue can be exploited?
The attacker must first compromise the Chrome renderer process and then use social engineering to get the target to interact with a crafted HTML page. The issue may then allow arbitrary code execution outside Chrome’s sandbox.
2
Which Chrome versions are affected?
Google Chrome versions prior to 153.0.8010.36 are affected.
3
Is visiting a crafted page alone sufficient for exploitation?
No. The available information states that exploitation also requires a compromised renderer process and social engineering.