CVE-2026-87457
Google · Chrome
A race condition in the Google Chrome Updater for Windows allows a local attacker to execute arbitrary code outside the sandbox.
Executive summary
A critical race condition vulnerability in the Google Chrome Updater for Windows allows local attackers to achieve arbitrary code execution, bypassing sandbox protections.
Vulnerability
The vulnerability is a race condition (CWE-367) within the Google Chrome Updater component on Windows. An unauthenticated local attacker can leverage this flaw to execute arbitrary code with elevated privileges, effectively escaping the browser sandbox.
Business impact
The ability for a local attacker to execute arbitrary code outside the browser sandbox poses a severe threat to system integrity and confidentiality. With a CVSS score of 8.1, this vulnerability allows for full system compromise, potentially leading to unauthorized data access, the installation of persistent malware, or lateral movement within the network.
Remediation
Immediate Action: Update Google Chrome on all Windows systems to version 153.0.8010.36 or later to incorporate the vendor-supplied security fix.
Proactive Monitoring: Monitor system logs for unusual process creation events or unexpected modifications to files within the Google Chrome installation directory.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced for local user accounts, as the vulnerability requires local access to the system to initiate the exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity of this vulnerability and its potential to bypass critical security boundaries, organizations should prioritize the deployment of the 153.0.8010.36 update across their Windows environments. Failure to patch may leave systems vulnerable to local privilege escalation and subsequent full system compromise.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written