CVE-2026-87460

8.8

Google · Chrome

A use-after-free vulnerability in Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome allows remote attackers to execute arbitrary code on affected systems via malicious web content.

Vulnerability

This flaw is a use-after-free vulnerability (CWE-416) within the Platform component of Google Chrome. It allows an unauthenticated remote attacker to trigger memory corruption and achieve arbitrary code execution inside the browser sandbox by enticing a user to view a specially crafted HTML page.

Business impact

Successful exploitation of this vulnerability could lead to complete system compromise within the context of the browser, potentially allowing attackers to bypass security boundaries. Given the CVSS score of 8.8, this represents a significant risk to organizational endpoints, as it facilitates remote code execution that can result in data theft or further lateral movement within the network.

Remediation

Immediate Action: Update all installations of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Review endpoint security logs for unusual browser crashes or unexpected process spawned by the Chrome application, which may indicate attempted exploitation.

Compensating Controls: Ensure that browser-based security features, such as site isolation and sandboxing, are enabled and enforced via group policy. Deploying a robust endpoint detection and response solution can help identify and block malicious script execution triggered by the browser.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates a rapid response to minimize the window of exposure. Administrators should prioritize the deployment of the Chrome update across all managed workstations to remediate the underlying memory management flaw and protect against potential remote code execution attacks.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources