CVE-2026-87542

8.8

Google · Chrome

A use after free vulnerability in Google Chrome's input handling allows a remote attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code via malicious web content.

Vulnerability

This is a use after free flaw (CWE-416) within the browser's input processing engine, which can be triggered by an unauthenticated remote attacker when a user navigates to a specially crafted HTML page.

Business impact

Successful exploitation allows a remote attacker to execute arbitrary code within the browser sandbox, potentially leading to a complete compromise of the user's browser session. Given the CVSS score of 8.8, this vulnerability poses a significant risk to organizational data confidentiality and integrity, as browser-based attacks are frequently used as initial access vectors for broader network compromise.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later to incorporate the vendor-provided security fix.

Proactive Monitoring: Review endpoint security logs for unusual browser process behavior or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that enterprise security policies enforce browser sandboxing and consider using browser isolation technologies to mitigate the impact of code execution within the rendering engine.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk due to the potential for arbitrary code execution in a widely used browser. Organizations must prioritize the deployment of the 153.0.8010.36 update across all workstations to remediate this flaw and prevent potential browser-based attacks.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources