CVE-2026-87500

Google · Chrome

A memory safety vulnerability involving improper array index validation in the ANGLE component of Google Chrome allows for remote code execution via a crafted HTML page.

Executive summary

A critical vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox through a specially crafted HTML page.

Vulnerability

This flaw is caused by improper validation of array indices within the ANGLE graphics engine component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a malicious website, leading to potential sandbox escape and arbitrary code execution.

Business impact

The impact of this vulnerability is severe, as it facilitates full system compromise or unauthorized access to sensitive user data by bypassing the browser sandbox. With a CVSS score of 9.6, this vulnerability represents a critical risk to organizational security, potentially resulting in significant data breaches or the deployment of persistent malware on employee workstations.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected crashes associated with the Chrome browser process.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web content or anomalous browser behavior, and ensure that users are restricted from executing untrusted scripts where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this flaw and its potential for sandbox escape, organizations must prioritize the deployment of the browser update across all endpoints. Promptly patching this vulnerability is the most effective method to mitigate the risk of remote code execution and prevent potential compromise of the corporate environment.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources