CVE-2026-87500
Google · Chrome
A memory safety vulnerability involving improper array index validation in the ANGLE component of Google Chrome allows for remote code execution via a crafted HTML page.
Executive summary
A critical vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox through a specially crafted HTML page.
Vulnerability
This flaw is caused by improper validation of array indices within the ANGLE graphics engine component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a malicious website, leading to potential sandbox escape and arbitrary code execution.
Business impact
The impact of this vulnerability is severe, as it facilitates full system compromise or unauthorized access to sensitive user data by bypassing the browser sandbox. With a CVSS score of 9.6, this vulnerability represents a critical risk to organizational security, potentially resulting in significant data breaches or the deployment of persistent malware on employee workstations.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected crashes associated with the Chrome browser process.
Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web content or anomalous browser behavior, and ensure that users are restricted from executing untrusted scripts where possible.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this flaw and its potential for sandbox escape, organizations must prioritize the deployment of the browser update across all endpoints. Promptly patching this vulnerability is the most effective method to mitigate the risk of remote code execution and prevent potential compromise of the corporate environment.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written