CVE-2026-87474

9.6

Google · Chrome

A use after free vulnerability in the Google Chrome Payments component allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

Google Chrome contains a critical use after free vulnerability in the Payments component that allows remote code execution via a malicious webpage.

Vulnerability

This is a use after free flaw (CWE-416) within the Payments component of the browser. It allows an unauthenticated, remote attacker to trigger arbitrary code execution outside the browser sandbox by enticing a user to visit a specially crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 9.6, indicating a critical risk to organizational security. Successful exploitation allows for complete system compromise, potentially leading to unauthorized data exfiltration, the installation of persistent malware, and complete loss of confidentiality, integrity, and availability for the affected endpoint.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected process spawns originating from the Chrome application.

Compensating Controls: While browser-level patching is the only definitive fix, ensure that endpoint protection platforms are active and configured to detect malicious web traffic or suspicious memory manipulation patterns.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS severity and the nature of use after free vulnerabilities in web browsers, immediate remediation is required. Security teams should prioritize the deployment of the 153.0.8010.36 update across all managed workstations to eliminate the risk of remote code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources