CVE-2026-87533
Google · Chrome
A use after free vulnerability in Google Chrome DevTools allows a local attacker to achieve arbitrary code execution outside of the browser sandbox.
Executive summary
A use after free flaw in Google Chrome DevTools permits local attackers to execute arbitrary code, posing a significant risk to system integrity.
Vulnerability
This vulnerability is a use after free condition within the DevTools component of Google Chrome. It can be triggered by an unauthenticated local attacker to execute arbitrary code outside the browser sandbox.
Business impact
The ability to execute arbitrary code outside of the browser sandbox creates a severe security risk that could lead to a full system compromise. Given the CVSS score of 8.1, this vulnerability represents a high risk to organizational security, as it allows attackers to bypass core security boundaries and potentially gain unauthorized access to sensitive data or system resources.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor security patch.
Proactive Monitoring: Monitor local system logs for unusual process execution patterns or attempts by browser processes to access unauthorized system files.
Compensating Controls: Restrict local user access to sensitive system directories and enforce the principle of least privilege to limit the impact if a browser process is compromised.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should prioritize updating all instances of Google Chrome to the fixed version. Although local access is required, the severity of a sandbox escape necessitates prompt remediation to prevent potential privilege escalation or persistent system compromise.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.1 (3.1)
- Analyst report written