CVE-2026-87480

Google · Chrome

A use after free vulnerability in the Printing component of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to bypass sandbox protections and achieve code execution through malicious web content.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Printing component of the browser. An unauthenticated remote attacker can exploit this flaw by enticing a user to visit a crafted HTML page, leading to potential code execution outside the browser sandbox.

Business impact

The vulnerability carries a CVSS score of 8.3, indicating a high level of risk to organizational infrastructure. Successful exploitation could result in full system compromise, unauthorized data access, and the potential for lateral movement within the network. Because the vulnerability involves bypassing the browser sandbox, the impact to workstations and the data accessible to the end user is significant.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to address this security flaw.

Proactive Monitoring: Monitor endpoint logs for unusual browser activity or crashes associated with the printing service, which may indicate attempted exploitation.

Compensating Controls: Ensure that browser-level protections are enabled and consider using endpoint detection and response (EDR) solutions to identify and block suspicious child processes spawned by the browser.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential remote code execution via a browser-based vector, organizations must prioritize the deployment of the patch to all workstations running Google Chrome. Failure to update in a timely manner leaves the organization vulnerable to drive-by download attacks. Administrators should confirm that automatic updates are functioning correctly and verify the version status across the enterprise fleet.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources