Skip to content
Auto-CTI
Back to today
NEW HIGH A3

CVE-2026-87547 , Google Chrome Incorrect FileSystem Reference Resolution Allows Sandbox Escape via Social Engineering

A NVD · · CVE-2026-87547

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

The vulnerability enables sandbox escape via incorrect filesystem reference resolution and requires active social engineering; however, there is no evidence of active exploitation in the wild.

Description

CVE-2026-87547 is a vulnerability in Google Chrome prior to version 153.0.8010.36 caused by incorrect reference resolution in the filesystem module. An attacker can exploit this through a crafted HTML page combined with social engineering to potentially execute arbitrary code outside the sandbox isolation. Chromium security severity is rated as "Medium". No active campaigns or PoC exploits are mentioned; this is preventive patch information.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC