CVE-2026-87533

Google · Chrome

A use after free vulnerability in Google Chrome DevTools allows a local attacker to achieve arbitrary code execution outside of the browser sandbox.

Executive summary

A use after free flaw in Google Chrome DevTools permits local attackers to execute arbitrary code, posing a significant risk to system integrity.

Vulnerability

This vulnerability is a use after free condition within the DevTools component of Google Chrome. It can be triggered by an unauthenticated local attacker to execute arbitrary code outside the browser sandbox.

Business impact

The ability to execute arbitrary code outside of the browser sandbox creates a severe security risk that could lead to a full system compromise. Given the CVSS score of 8.1, this vulnerability represents a high risk to organizational security, as it allows attackers to bypass core security boundaries and potentially gain unauthorized access to sensitive data or system resources.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor security patch.

Proactive Monitoring: Monitor local system logs for unusual process execution patterns or attempts by browser processes to access unauthorized system files.

Compensating Controls: Restrict local user access to sensitive system directories and enforce the principle of least privilege to limit the impact if a browser process is compromised.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize updating all instances of Google Chrome to the fixed version. Although local access is required, the severity of a sandbox escape necessitates prompt remediation to prevent potential privilege escalation or persistent system compromise.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.1 (3.1)
  4. Analyst report written

Sources