CVE-2026-87444

8.8

Google · Chrome

A memory corruption vulnerability in the Google Chrome Codecs component allows a remote attacker to execute arbitrary code via a specially crafted HTML page.

Executive summary

Google Chrome versions prior to 153.0.8010.36 are vulnerable to a memory corruption flaw that could allow a remote attacker to achieve arbitrary code execution.

Vulnerability

This is a memory corruption vulnerability within the Codecs component of the browser. It allows an unauthenticated remote attacker to execute arbitrary code within the sandboxed environment when a user visits a maliciously crafted HTML page.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the browser environment. Given the CVSS score of 8.8, this represents a high risk, as it could facilitate further system exploitation, unauthorized data access, or the deployment of malicious payloads on user workstations.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual browser processes or unexpected network connections originating from the Chrome application.

Compensating Controls: While browser-based exploits are difficult to block via network controls alone, ensure that endpoint protection platforms are updated to detect known exploit patterns associated with memory corruption.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high severity of this vulnerability, combined with the potential for remote code execution, necessitates prompt action. Administrators should prioritize the deployment of the 153.0.8010.36 update across all enterprise endpoints to eliminate the risk posed by this memory corruption flaw.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources