Junglewise Threat Intelligence

CVE-2026-87535: Google Chrome Safe Browsing bypass in macOS

CVE-2026-87535 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome's Safe Browsing feature on macOS failed to properly validate HTML pages, allowing attackers to bypass system access restrictions. An attacker could craft a malicious webpage to circumvent security controls that Chrome uses to protect users from harmful content and phishing sites.

Technical details

This is an information loss or omission vulnerability in Chrome's Safe Browsing component on macOS prior to version 153.0.8010.36. The flaw allows a remote attacker to bypass system access restrictions by serving a crafted HTML page, without requiring user authentication or special privileges. The vulnerability has a Chromium-assigned medium severity rating and was patched in Chrome 153.0.8010.36 released on September 8, 2026. No evidence of active exploitation in the wild has been reported.

Affected products

  • Google Chrome prior to 153.0.8010.36 on macOS

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats