CVE-2026-87494

Google · Chrome

A use after free vulnerability in the Google Chrome browser on Windows allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome on Windows permits remote code execution, posing a severe risk to end user systems.

Vulnerability

This is a use after free flaw (CWE-416) within the browser component. It allows an unauthenticated remote attacker to achieve arbitrary code execution outside the sandbox when a user is tricked into interacting with a malicious HTML page.

Business impact

Successful exploitation leads to full system compromise, as the vulnerability allows code execution outside the browser sandbox. Given the CVSS score of 9.6, this represents a critical risk that could lead to unauthorized data access, malware installation, and complete loss of system integrity.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual process spawning or suspicious network activity originating from browser instances.

Compensating Controls: Ensure that endpoint protection solutions are active and configured to block execution of unauthorized binaries, which may help contain potential post-exploitation activity.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the high severity of this vulnerability and the potential for remote code execution, organizations must prioritize the deployment of the 153.0.8010.36 update across all Windows workstations. Users should be reminded to exercise caution when navigating to untrusted websites, as the attack vector requires social engineering to initiate the exploit chain.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources