CVE-2026-87440

8.8

Google · Chrome

A memory safety flaw in Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

Google Chrome versions prior to 153.0.8010.36 are vulnerable to an out of bounds read flaw that could allow a remote attacker to execute arbitrary code within the browser sandbox.

Vulnerability

The vulnerability is an out of bounds read (CWE-125) occurring within the Media component of Chrome. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution within the browser's security sandbox.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational security, as it allows attackers to bypass browser protections and potentially access sensitive user data, credentials, or local system resources. With a CVSS score of 8.8, this high severity vulnerability necessitates immediate attention to prevent compromise of endpoints that serve as critical access points for business operations.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint logs for suspicious browser behavior, including unexpected crashes or unauthorized attempts to access sensitive file paths from the browser process.

Compensating Controls: Deploy endpoint protection platforms that utilize behavioral analysis to detect and block malicious code execution attempts originating from web browser processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the prevalence of the Chrome browser in enterprise environments, organizations must prioritize the deployment of the 153.0.8010.36 update. Failure to patch this vulnerability leaves endpoints susceptible to remote code execution attacks, which could lead to severe data breaches or system instability. Please ensure that all browser instances are updated across the fleet to mitigate this risk effectively.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources