Executive brief
Google Chrome's Safe Browsing protection feature on macOS contains a type conversion flaw that allows an attacker to bypass system access restrictions. An attacker can exploit this vulnerability by tricking a user into opening a specially crafted file, potentially circumventing security protections that prevent malicious software from accessing sensitive system resources.
Technical details
The vulnerability is a type conversion or cast error in the Safe Browsing component of Google Chrome on macOS. This flaw allows a remote attacker to bypass system access restrictions via a crafted file. The vulnerability requires user interaction (opening a malicious file) to be exploited. The fix is available in Chrome version 153.0.8010.36 and later for Mac. Google assigned this a Low severity rating within Chromium's security classification, though it is tracked as CVE-2026-87546.
Affected products
- Google Chrome prior to 153.0.8010.36 on macOS
Timeline
- 2026-09-09: disclosed: CVE-2026-87546 disclosed in NVD
- 2026-09-08: patched: Chrome 153.0.8010.36 released with fix