CVE-2026-87512
9.6Google · Chrome
A use after free vulnerability in the ANGLE component of Google Chrome on Windows allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome for Windows allows unauthenticated remote attackers to achieve arbitrary code execution via malicious web content.
Vulnerability
This is a use after free flaw (CWE-416) within the ANGLE graphics engine. It allows an unauthenticated remote attacker to trigger memory corruption and execute arbitrary code outside the browser sandbox when a user visits a specially crafted HTML page.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it could lead to full system compromise or the installation of persistent malware. With a CVSS score of 9.6, this vulnerability is classified as critical, reflecting the high probability of total confidentiality, integrity, and availability loss if exploited.
Remediation
Immediate Action: Update all Google Chrome instances on Windows platforms to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution spawned by the Chrome application.
Compensating Controls: Ensure that browser security settings are strictly enforced via Group Policy and utilize endpoint detection and response tools to identify and block suspicious child processes initiated by the browser.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the potential for complete sandbox escape, immediate deployment of the 153.0.8010.36 update is mandatory. IT administrators should prioritize this update across all corporate Windows workstations to prevent unauthorized code execution and maintain the integrity of the endpoint environment.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry