Junglewise Threat Intelligence

CVE-2026-87546: Google Chrome Safebrowsing type conversion security bypass on Mac

CVE-2026-87546 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome's Safe Browsing protection feature on macOS contains a type conversion flaw that allows an attacker to bypass system access restrictions. An attacker can exploit this vulnerability by tricking a user into opening a specially crafted file, potentially circumventing security protections that prevent malicious software from accessing sensitive system resources.

Technical details

The vulnerability is a type conversion or cast error in the Safe Browsing component of Google Chrome on macOS. This flaw allows a remote attacker to bypass system access restrictions via a crafted file. The vulnerability requires user interaction (opening a malicious file) to be exploited. The fix is available in Chrome version 153.0.8010.36 and later for Mac. Google assigned this a Low severity rating within Chromium's security classification, though it is tracked as CVE-2026-87546.

Affected products

  • Google Chrome prior to 153.0.8010.36 on macOS

Timeline

  • 2026-09-09: disclosed: CVE-2026-87546 disclosed in NVD
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats