CVE-2026-87504
Google · Chrome
A use after free vulnerability in the Google Chrome Core component allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted extension.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a severe risk to system integrity and user security.
Vulnerability
This vulnerability involves a use after free condition in the Chrome Core component, which can be triggered by an unauthenticated remote attacker through social engineering to achieve code execution outside the sandbox.
Business impact
The ability for an attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected host system. Given the CVSS score of 9.6, this vulnerability carries a critical severity rating, potentially leading to unauthorized data access, full system control, and significant reputational or operational damage.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patch.
Proactive Monitoring: Review browser extension deployment logs and monitor endpoint activity for anomalous process creation or unexpected network connections originating from the Chrome browser.
Compensating Controls: Implement browser management policies that restrict the installation of unauthorized extensions and utilize endpoint detection and response tools to identify malicious post-exploitation behavior.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical nature of this vulnerability and its potential for full system compromise, organizations should prioritize the deployment of the 153.0.8010.36 update across all managed Chrome instances. Prompt remediation is essential to prevent attackers from leveraging this flaw to bypass browser security controls and gain persistent access to underlying host systems.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written