Junglewise Threat Intelligence

CVE-2026-87627: Google Chrome Safe Browsing interpretation conflict on Mac

CVE-2026-87627 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome's Safe Browsing feature on macOS contains a flaw that allows attackers to bypass system access restrictions through social engineering and a crafted file. An attacker could trick a user into opening a malicious file that the browser would incorrectly permit, potentially leading to unauthorized system access or compromise.

Technical details

This vulnerability is an interpretation conflict in the Safe Browsing component of Google Chrome on macOS, allowing attackers to bypass access restrictions via a crafted file. The flaw requires social engineering to trick a user into interacting with the malicious content, as it is not a direct network-based attack. Attackers can exploit this to circumvent browser protections that normally block or warn about potentially harmful files. The vulnerability affects Chrome versions prior to 153.0.8010.36 on macOS and has been patched in the Chrome 153 stable release (September 8, 2026).

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats