Junglewise Threat Intelligence

CVE-2026-87582: Google Chrome confused deputy in DataTransfer

CVE-2026-87582 · Severity: high · CVSS 8.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in its DataTransfer component that allows an attacker who has compromised the browser's renderer process to break out of the security sandbox and execute arbitrary code. This could enable an attacker to fully compromise a user's system and steal sensitive data or install malware.

Technical details

The vulnerability is a confused deputy issue in Chrome's DataTransfer component that permits a compromised renderer process to execute arbitrary code outside the sandbox. The attack vector requires prior renderer process compromise, achieved through a malicious HTML page. The flaw allows privilege escalation from the sandboxed renderer to the main browser process, bypassing Chrome's process isolation security model. This issue was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats