Vulnerability record

CVE-2026-87499

Severity: HighExploitation: No known exploitation

Patch status

Official fix available since

Apply the vendor's update to every affected system. Check the fixed-in versions below where known.

Basis: Google Chrome Releases vendor advisory

Description

Incorrect authorization in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Affected products

Products affected by this vulnerability, with versions and the source of each entry
ProductVendorAffected versionsFixed inSource
ChromeGoogle< 153.0.8010.36153.0.8010.36NVD

Sources: NVD = NIST National Vulnerability Database.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdate

    CVE-2026-87499 scored CVSS 8.1

    Basis: NIST National Vulnerability Database

Coverage

References

CVE-2026-87499 | CybersecurityNews.us