CVE-2026-87504

Google · Chrome

A use after free vulnerability in the Google Chrome Core component allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted extension.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a severe risk to system integrity and user security.

Vulnerability

This vulnerability involves a use after free condition in the Chrome Core component, which can be triggered by an unauthenticated remote attacker through social engineering to achieve code execution outside the sandbox.

Business impact

The ability for an attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected host system. Given the CVSS score of 9.6, this vulnerability carries a critical severity rating, potentially leading to unauthorized data access, full system control, and significant reputational or operational damage.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review browser extension deployment logs and monitor endpoint activity for anomalous process creation or unexpected network connections originating from the Chrome browser.

Compensating Controls: Implement browser management policies that restrict the installation of unauthorized extensions and utilize endpoint detection and response tools to identify malicious post-exploitation behavior.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of this vulnerability and its potential for full system compromise, organizations should prioritize the deployment of the 153.0.8010.36 update across all managed Chrome instances. Prompt remediation is essential to prevent attackers from leveraging this flaw to bypass browser security controls and gain persistent access to underlying host systems.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources