CVE-2026-87529

9.6

Google · Chrome

A numeric truncation error in the Media component of Google Chrome allows a remote attacker to execute arbitrary code outside the browser sandbox via a specially crafted HTML page.

Executive summary

A critical vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution by enticing a user to view a malicious webpage.

Vulnerability

The flaw is a numeric truncation error (CWE-197) located within the browser's Media handling logic. This vulnerability can be triggered by an unauthenticated attacker who successfully lures a victim to a malicious website.

Business impact

The potential for arbitrary code execution outside the browser sandbox represents a severe threat to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent malware, justifying the critical CVSS score of 9.6.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or higher immediately to apply the vendor-supplied fix.

Proactive Monitoring: Review endpoint security logs for unusual process spawning activities originating from the Chrome browser executable.

Compensating Controls: Deploy browser isolation solutions or ensure that endpoint detection and response tools are configured to block suspicious child processes initiated by web browsers.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this vulnerability and its potential to bypass browser-level security protections, organizations must prioritize the deployment of the Chrome update across all workstations. Failure to patch creates a significant window of opportunity for attackers to gain elevated control over end-user systems.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources