Junglewise Threat Intelligence

CVE-2026-87468: Google Chrome site isolation bypass in Isolated

CVE-2026-87468 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's site isolation feature, a security mechanism designed to prevent one website from accessing data belonging to another, contains an authorization flaw. An attacker can craft a malicious HTML page to bypass this protection, potentially allowing unauthorized access to sensitive data from other websites that a user visits.

Technical details

CVE-2026-87468 is an incorrect authorization vulnerability in Chrome's Isolated component that fails to properly enforce site isolation boundaries. The flaw allows a remote attacker to craft a malicious HTML page that, when visited by a user, can bypass site isolation protections. No authentication or special user interaction beyond viewing the crafted page is required. An attacker can exploit this to access cross-origin data that should be protected by site isolation. The vulnerability was patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome before 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats