CVE-2026-87535 Details
Description
Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
A vulnerability in Google Chrome's Safebrowsing feature on Mac, prior to version 153.0.8010.36, allowed remote attackers to bypass system access restrictions. This was achieved by exploiting a logic flaw in the DMGAnalyzer, which is responsible for processing files within DMG archives. The analyzer failed to record certain non-Mach-O file types, such as .pkg, .command, and .tar, as archived binaries. As a result, malicious payloads hidden inside a DMG could evade detection by Safebrowsing's telemetry system.
Users should update Google Chrome to version 153.0.8010.36 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html | [email protected] | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/520572550 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-221 | Information Loss or Omission | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 153.0.8010.36 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 10, 2026 | Initial Analysis | [email protected] |
| Sep 10, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |