CVE-2026-87553: Input Validation
Improper input validation in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need before this issue can be exploited?
The attacker must already have compromised the Chrome renderer process. The issue can then be triggered with a crafted HTML page to potentially execute code outside the sandbox.
Are users exposed simply by visiting a malicious page?
The provided information does not describe this as a standalone drive-by compromise. Exploitation requires a prior renderer-process compromise, with the crafted HTML page used to leverage the sandbox escape.
Which Chrome versions should be remediated?
Google Chrome versions prior to 153.0.8010.36 are affected. Update Chrome to 153.0.8010.36 or later.