CVE-2026-87520
9.6Google · Chrome
A use after free vulnerability in the Dawn component of Google Chrome on Android allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
Google Chrome for Android is affected by a critical use after free vulnerability that enables remote code execution outside the browser sandbox.
Vulnerability
This is a use after free flaw occurring within the Dawn component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution.
Business impact
The ability for an attacker to execute code outside the browser sandbox presents a severe risk to device integrity and user data privacy. Given the CVSS score of 9.6, this vulnerability is classified as critical, as it facilitates full compromise of the affected device by bypassing standard security boundaries.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Review web access logs for signs of users visiting suspicious or untrusted domains that may attempt to deliver malicious HTML content.
Compensating Controls: Ensure Google Play Protect is enabled on all Android devices to provide an additional layer of defense against malicious applications and web-based exploits.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the potential for sandbox escape, necessitates immediate action. Administrators and end users should prioritize updating Google Chrome to the fixed version to eliminate the risk of remote code execution and maintain the security posture of their mobile environment.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry