CVE-2026-87430

8.8

Google · Chrome

A buffer overflow vulnerability in the WebRTC component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical buffer overflow vulnerability in Google Chrome WebRTC enables remote code execution, posing a significant risk to user systems.

Vulnerability

This vulnerability is a buffer overflow (CWE-122) located in the WebRTC component. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a malicious website or view a crafted HTML page.

Business impact

Successful exploitation permits a remote attacker to execute arbitrary code within the browser sandbox, which could lead to full system compromise if subsequent sandbox escape techniques are employed. With a CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it facilitates data theft, malware installation, and unauthorized control over user workstations.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity, such as unexpected child process creation or unauthorized network connections originating from the browser.

Compensating Controls: Deploy endpoint protection solutions that detect and block malicious web content and enforce strict browser security policies via Group Policy or MDM solutions to limit the impact of potential code execution.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the capability for remote code execution, organizations must prioritize the deployment of the browser update across all managed devices. Ensuring that browser auto-update mechanisms are functional and unencumbered is essential to mitigating this high-severity risk effectively.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources