CVE-2026-87553: Input Validation
Chromium CVE-2026-87553: Improper input validation in SiteIsolation
Other sources
Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Chromium / Google Chrome (SiteIsolation)to a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
What level of access does an attacker need before this issue can be exploited?
The attacker must already have compromised the Chrome renderer process. The issue can then be triggered with a crafted HTML page to potentially execute code outside the sandbox.
Are users exposed simply by visiting a malicious page?
The provided information does not describe this as a standalone drive-by compromise. Exploitation requires a prior renderer-process compromise, with the crafted HTML page used to leverage the sandbox escape.
Which Chrome versions should be remediated?
Google Chrome versions prior to 153.0.8010.36 are affected. Update Chrome to 153.0.8010.36 or later.