CVE-2026-87528

9.6

Google · Chrome

A type confusion vulnerability in Rust within Google Chrome for Windows allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

A critical type confusion vulnerability in Google Chrome for Windows allows unauthenticated remote attackers to achieve arbitrary code execution through malicious web content.

Vulnerability

This flaw involves a type confusion error in the Rust implementation within the browser, which can be triggered by an unauthenticated remote attacker when a user visits a specifically crafted HTML page.

Business impact

The ability to execute arbitrary code outside the browser sandbox poses a severe risk to organizational security, potentially leading to full system compromise, data exfiltration, or the deployment of persistent malware. While the vendor classifies the internal severity as Medium, the CVSS score of 9.6 reflects the catastrophic potential for impact on confidentiality, integrity, and availability should an attacker successfully weaponize this flaw.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or higher immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor browser-related crash logs and endpoint security telemetry for unusual process spawning or memory access patterns that may indicate exploitation attempts.

Compensating Controls: Ensure users are operating with the principle of least privilege, and deploy endpoint protection platforms capable of detecting browser-based exploitation techniques.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS score of 9.6, this vulnerability represents a high-priority risk that requires immediate attention. Administrators must prioritize the deployment of the Chrome update across all Windows workstations to prevent potential remote code execution, as the sandbox escape capability significantly lowers the barrier for a successful and damaging attack.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources