CVE-2026-87489
8.8Google · Chrome
A memory corruption vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a malicious browser extension.
Executive summary
A memory corruption vulnerability in Google Chrome version 153.0.8010.36 and earlier poses a significant risk of remote code execution through crafted browser extensions.
Vulnerability
This vulnerability involves memory corruption within the V8 JavaScript engine, which can be triggered by an unauthenticated remote attacker using a specially crafted Chrome extension. Successful exploitation allows for arbitrary code execution within the browser sandbox.
Business impact
The ability for a remote attacker to achieve arbitrary code execution introduces a high risk of data theft, session hijacking, and potential lateral movement within the user environment. With a CVSS score of 8.8, this vulnerability represents a high severity threat that could compromise the integrity and confidentiality of sensitive information processed by the browser.
Remediation
Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to apply the necessary memory safety patches.
Proactive Monitoring: Monitor enterprise browser logs and endpoint security telemetry for the installation of unauthorized or suspicious browser extensions.
Compensating Controls: Enforce strict browser extension management policies via Group Policy or Mobile Device Management (MDM) to restrict the installation of unapproved extensions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for remote code execution, this vulnerability should be treated as a priority for all workstation environments. Organizations must ensure that the update cycle for Google Chrome is strictly followed to mitigate this risk, and security teams should audit currently installed browser extensions to ensure only verified and necessary software is present on managed endpoints.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Analyst report written
- Published in the daily brief high section