CVE-2026-87474
9.6Google · Chrome
A use after free vulnerability in the Google Chrome Payments component allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Executive summary
Google Chrome contains a critical use after free vulnerability in the Payments component that allows remote code execution via a malicious webpage.
Vulnerability
This is a use after free flaw (CWE-416) within the Payments component of the browser. It allows an unauthenticated, remote attacker to trigger arbitrary code execution outside the browser sandbox by enticing a user to visit a specially crafted HTML page.
Business impact
The vulnerability carries a CVSS score of 9.6, indicating a critical risk to organizational security. Successful exploitation allows for complete system compromise, potentially leading to unauthorized data exfiltration, the installation of persistent malware, and complete loss of confidentiality, integrity, and availability for the affected endpoint.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected process spawns originating from the Chrome application.
Compensating Controls: While browser-level patching is the only definitive fix, ensure that endpoint protection platforms are active and configured to detect malicious web traffic or suspicious memory manipulation patterns.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity and the nature of use after free vulnerabilities in web browsers, immediate remediation is required. Security teams should prioritize the deployment of the 153.0.8010.36 update across all managed workstations to eliminate the risk of remote code execution.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry