Skip to content
Auto-CTI
Back to today
NEW HIGH A3

CVE-2026-87530: Uncontrolled Search Path Element in CredentialProvider in Google Chrome on Windows prior to 153.0.8010.36

A NVD · · CVE-2026-87530

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

The vulnerability allows local attackers with existing access to the Windows system to execute arbitrary code outside the browser sandbox through an improper search path in the CredentialProvider component.

Description

CVE-2026-87530 is a vulnerability in the CredentialProvider component of Google Chrome on Windows systems. The flaw involves an uncontrolled search path element that allows a local attacker to execute arbitrary code outside the sandbox. The vulnerability affects Chrome versions prior to 153.0.8010.36 and was classified by Google with medium severity. Affected systems can be compromised by a local program on the same machine. Sandbox escape enables privilege escalation and deeper system access.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC