CVE-2026-87448
9.6Google · Chrome
A use after free vulnerability in Google Chrome DevTools allows a remote, unauthenticated attacker to execute arbitrary code outside the browser sandbox via a specially crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome enables remote code execution, posing a significant risk to user systems and data integrity.
Vulnerability
This flaw is a use after free vulnerability residing within the DevTools component of Google Chrome. An unauthenticated remote attacker can trigger this condition by enticing a user to navigate to a malicious HTML page, leading to potential code execution outside the sandbox.
Business impact
The ability to execute arbitrary code outside the browser sandbox represents a severe security failure that can lead to full system compromise. Given the CVSS score of 9.6, this vulnerability is classified as critical, as it bypasses standard browser security boundaries and could allow an attacker to gain persistent access to the underlying host, resulting in data theft or malware installation.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor network traffic for unusual patterns associated with browser-based exploitation and review endpoint security logs for signs of unauthorized process execution.
Compensating Controls: Utilize endpoint protection platforms that provide behavioral analysis to detect and block malicious code execution attempts occurring from web browser processes.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability, immediate deployment of the updated version of Google Chrome is required across all organizational endpoints. Administrators should prioritize this update to prevent potential exploitation and ensure that security patches are applied before any public proof-of-concept code becomes available.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry