CVE-2026-87514
Google · Chrome
A use after free vulnerability in the Views component of Google Chrome allows a local attacker to achieve arbitrary code execution outside the sandbox.
Executive summary
A high-severity use after free vulnerability in Google Chrome allows local attackers to execute arbitrary code and bypass sandbox protections.
Vulnerability
This is a use after free vulnerability (CWE-416) within the Views component. An unauthenticated local attacker can leverage this flaw to execute arbitrary code outside the browser sandbox by executing a specially crafted local program.
Business impact
The ability for an attacker to execute code outside the browser sandbox poses a significant risk to system integrity and confidentiality. With a CVSS score of 8.1, this vulnerability is categorized as High, as it allows a local actor to elevate their privileges and potentially take full control of the host operating system. This could lead to total data compromise or the installation of persistent malicious software on affected workstations.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Monitor system logs for unauthorized local process execution or unexpected attempts to access protected memory spaces.
Compensating Controls: While this is a local attack vector, ensure that endpoint detection and response (EDR) agents are updated to detect anomalous process behavior and unauthorized privilege escalation attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the capability for arbitrary code execution, this vulnerability represents a critical risk to host security. Administrators should prioritize the deployment of the 153.0.8010.36 update across all enterprise environments to ensure the browser sandbox remains effective against local threats.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written