CVE-2026-87547 , Google Chrome Incorrect FileSystem Reference Resolution Allows Sandbox Escape via Social Engineering
A NVD · · CVE-2026-87547
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- EPSS
- 0%
Key insight
The vulnerability enables sandbox escape via incorrect filesystem reference resolution and requires active social engineering; however, there is no evidence of active exploitation in the wild.
Description
CVE-2026-87547 is a vulnerability in Google Chrome prior to version 153.0.8010.36 caused by incorrect reference resolution in the filesystem module. An attacker can exploit this through a crafted HTML page combined with social engineering to potentially execute arbitrary code outside the sandbox isolation. Chromium security severity is rated as "Medium". No active campaigns or PoC exploits are mentioned; this is preventive patch information.
Risk score
- cvss base
- 0.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 0.00
- raw before weight
- 0.00
- industry weight
- 1.21
- freshness factor
- 1.00
- exploitability factor
- 1.00
- days old
- 0.00
- vendor mismatch penalty
- 0.00
Path: operational