CVE-2026-87530: High severity Google Chrome vulnerability
Chromium CVE-2026-87530: Uncontrolled search path element in CredentialProvider
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Uncontrolled search path element in CredentialProvider in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium-based Edge on Windowsto a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
Who is exposed to this issue?
The issue affects Google Chrome on Windows before version 153.0.8010.36. Exploitation requires a local attacker and a local program.
What level of access does an attacker need?
An attacker needs local access sufficient to run or use a local program. The vulnerability can then allow arbitrary code execution outside Chrome's sandbox.
What is the remediation?
Update Google Chrome on Windows to version 153.0.8010.36 or later.