CVE-2026-87536
8.8Google · Chrome
A use-after-free vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use-after-free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution, posing a significant risk to end-user workstations.
Vulnerability
This vulnerability is a use-after-free flaw within the V8 JavaScript engine. An unauthenticated remote attacker can trigger this memory corruption by enticing a user to visit a specially crafted web page, resulting in arbitrary code execution within the browser sandbox.
Business impact
The ability for a remote attacker to execute arbitrary code on a user's machine creates a substantial risk of system compromise, data theft, and further movement within the corporate network. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to the complete loss of confidentiality, integrity, and availability of the affected endpoint.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary memory management fixes.
Proactive Monitoring: Monitor endpoint logs for abnormal browser process behavior or unexpected crash patterns that may indicate unsuccessful or successful exploitation attempts.
Compensating Controls: Ensure that browser-based security features, such as site isolation and sandboxing, are enabled and enforced via group policy to limit the potential impact of successful code execution.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high severity of this vulnerability, combined with its potential for remote code execution, necessitates immediate action across the enterprise. Security teams should prioritize the deployment of the Chrome update to all managed devices to neutralize this threat, as browser-based exploits remain a primary vector for initial system compromise.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section