CVE-2026-87464

9.6

Google · Chrome

A use after free vulnerability in the WebGL component of Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.

Executive summary

Google Chrome contains a critical use after free vulnerability in its WebGL component that allows a remote attacker to achieve arbitrary code execution.

Vulnerability

This vulnerability is a use after free (CWE-416) flaw within the WebGL engine. An unauthenticated remote attacker can trigger this memory corruption by enticing a user to visit a malicious HTML page, leading to code execution outside the browser sandbox.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it allows attackers to bypass browser security boundaries and gain control over the underlying host system. Given the CVSS score of 9.6, this vulnerability represents a critical threat to confidentiality, integrity, and availability. Successful exploitation could lead to full system compromise, data theft, or the installation of persistent malware.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected browser behavior that may indicate an attempt to exploit memory corruption vulnerabilities.

Compensating Controls: Ensure that browser-based security features, such as site isolation and the sandbox, are enabled and enforced via group policy. Deploying endpoint protection software that detects memory injection techniques can provide an additional layer of defense.

Exploitation status

Public Exploit Available: No confirmed public exploit (exploit_available: false).

Analyst recommendation

The severity of this vulnerability, combined with the potential for sandbox escape, necessitates immediate patching. Organizations should prioritize updating all Chrome browser installations across their fleet to version 153.0.8010.36 or newer to mitigate the risk of remote code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources