CVE-2026-87455
9.6Google · Chrome
A use after free vulnerability in the Aura component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, necessitating an immediate browser update.
Vulnerability
The vulnerability is a use after free condition within the Aura component, which can be triggered by a remote, unauthenticated attacker when a user visits a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code outside of the browser sandbox.
Business impact
This vulnerability carries a CVSS score of 9.6, indicating a critical risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent malware, posing a severe threat to both user privacy and corporate infrastructure.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately across all managed endpoints.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution or unexpected browser crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that all users operate with the principle of least privilege to limit the potential impact of code execution occurring outside the sandbox.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the potential for remote code execution, organizations must prioritize the deployment of the latest Chrome update. Administrators should verify that automatic updates are enabled and perform a forced version check to ensure all workstations are patched against this high-impact vulnerability.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry