CVE-2026-87467
Google · Chrome
A race condition in the Google Chrome Updater for Windows allows a local attacker to execute arbitrary code outside the sandbox.
Executive summary
A high-severity race condition in the Google Chrome Updater for Windows may allow local attackers to achieve arbitrary code execution outside the browser sandbox.
Vulnerability
This vulnerability is a race condition (CWE-362) located within the Google Chrome Updater component on Windows. It allows an unauthenticated local attacker to bypass sandbox protections and execute arbitrary code.
Business impact
The ability for a local attacker to escape the browser sandbox and execute arbitrary code poses a significant risk to endpoint security. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for persistent malware installation, justifying the high CVSS score of 8.1.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to incorporate the vendor-supplied fix.
Proactive Monitoring: Monitor endpoint security logs for unexpected process execution patterns or unauthorized attempts to access the Chrome Updater service.
Compensating Controls: Ensure that local user permissions are strictly managed and that endpoint detection and response (EDR) solutions are configured to alert on suspicious sub-process creation by browser-related binaries.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the potential for complete system compromise via sandbox escape, organizations should prioritize the deployment of the 153.0.8010.36 update across all Windows environments. Prompt application of this patch is essential to neutralize the risk of local code execution and maintain the integrity of the browser security model.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written