CVE-2026-87524
Google · Chrome
A use after free vulnerability in the Google Chrome Core component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution on affected Windows systems.
Vulnerability
This is a use after free vulnerability (CWE-416) located in the Core component of Google Chrome. The vulnerability allows an unauthenticated remote attacker who has successfully compromised the renderer process to escape the browser sandbox and execute arbitrary code on the underlying Windows system.
Business impact
The ability for an attacker to escape the browser sandbox and execute code at the system level poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, the theft of sensitive user data, and the deployment of malware across the corporate network. With a CVSS score of 8.3, this vulnerability is classified as high severity, reflecting the potential for significant impact on system confidentiality, integrity, and availability.
Remediation
Immediate Action: Update all Google Chrome instances on Windows to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patch.
Proactive Monitoring: Monitor endpoint security logs for unusual process spawning originating from the Chrome browser process or unexpected memory access violations.
Compensating Controls: Ensure that browser-based security policies, such as site isolation and sandboxing, are strictly enforced via Group Policy or centralized management tools.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote code execution and sandbox escape, this vulnerability represents a significant security risk to any organization utilizing Google Chrome on Windows. IT administrators should prioritize the deployment of the 153.0.8010.36 update across all workstations to ensure the vulnerability is mitigated before it can be weaponized by threat actors.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.3 (3.1)
- Analyst report written