CVE-2026-87542
8.8Google · Chrome
A use after free vulnerability in Google Chrome's input handling allows a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code via malicious web content.
Vulnerability
This is a use after free flaw (CWE-416) within the browser's input processing engine, which can be triggered by an unauthenticated remote attacker when a user navigates to a specially crafted HTML page.
Business impact
Successful exploitation allows a remote attacker to execute arbitrary code within the browser sandbox, potentially leading to a complete compromise of the user's browser session. Given the CVSS score of 8.8, this vulnerability poses a significant risk to organizational data confidentiality and integrity, as browser-based attacks are frequently used as initial access vectors for broader network compromise.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later to incorporate the vendor-provided security fix.
Proactive Monitoring: Review endpoint security logs for unusual browser process behavior or unexpected crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that enterprise security policies enforce browser sandboxing and consider using browser isolation technologies to mitigate the impact of code execution within the rendering engine.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant risk due to the potential for arbitrary code execution in a widely used browser. Organizations must prioritize the deployment of the 153.0.8010.36 update across all workstations to remediate this flaw and prevent potential browser-based attacks.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section