CVE-2026-87524

Google · Chrome

A use after free vulnerability in the Google Chrome Core component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution on affected Windows systems.

Vulnerability

This is a use after free vulnerability (CWE-416) located in the Core component of Google Chrome. The vulnerability allows an unauthenticated remote attacker who has successfully compromised the renderer process to escape the browser sandbox and execute arbitrary code on the underlying Windows system.

Business impact

The ability for an attacker to escape the browser sandbox and execute code at the system level poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, the theft of sensitive user data, and the deployment of malware across the corporate network. With a CVSS score of 8.3, this vulnerability is classified as high severity, reflecting the potential for significant impact on system confidentiality, integrity, and availability.

Remediation

Immediate Action: Update all Google Chrome instances on Windows to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Monitor endpoint security logs for unusual process spawning originating from the Chrome browser process or unexpected memory access violations.

Compensating Controls: Ensure that browser-based security policies, such as site isolation and sandboxing, are strictly enforced via Group Policy or centralized management tools.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and sandbox escape, this vulnerability represents a significant security risk to any organization utilizing Google Chrome on Windows. IT administrators should prioritize the deployment of the 153.0.8010.36 update across all workstations to ensure the vulnerability is mitigated before it can be weaponized by threat actors.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources