CVE-2026-87526

Google · Chrome

A use after free vulnerability in Google Chrome's password management component allows remote attackers to execute arbitrary code via social engineering and specific UI interactions.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a severe risk to system integrity and user security.

Vulnerability

This flaw is a use after free vulnerability occurring within the password management feature. An unauthenticated remote attacker can trigger this condition through social engineering, potentially leading to arbitrary code execution outside the browser sandbox.

Business impact

The potential for arbitrary code execution creates a high risk of total system compromise, including unauthorized data access and the installation of persistent malicious software. While the Chromium project classifies the internal severity as medium, the CVSS score of 9.6 reflects the catastrophic potential impact if code is executed with the privileges of the logged in user. Organizations face significant reputational and operational risks if these browser instances are used to access sensitive corporate assets.

Remediation

Immediate Action: Update all Google Chrome installations to version 153.0.8010.36 or later immediately to incorporate the vendor provided security patch.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process creation stemming from the Chrome application.

Compensating Controls: Deploy endpoint protection platforms that can detect and block suspicious exploit patterns or unauthorized code execution attempts within the browser process.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS severity and the potential for full sandbox escape, this vulnerability must be treated as a high priority for remediation. Administrators should ensure that automatic updates are enabled or push the update via centralized management tools immediately to mitigate the risk of remote code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources