CVE-2026-87547

9.6

Google · Chrome

A vulnerability in the Google Chrome FileSystem component allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page and social engineering.

Executive summary

A critical vulnerability in Google Chrome allows remote code execution outside the sandbox, posing a severe risk to user systems and data integrity.

Vulnerability

The flaw exists due to incorrect reference resolution within the FileSystem component, which can be triggered by an unauthenticated remote attacker using social engineering techniques to entice a user to visit a malicious HTML page.

Business impact

Successful exploitation of this vulnerability enables a remote attacker to achieve arbitrary code execution outside the browser sandbox, potentially leading to full system compromise. With a CVSS score of 9.6, this flaw represents an extreme risk to organizational security, as it could result in unauthorized data access, the installation of persistent malware, or lateral movement within the network.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary security fixes.

Proactive Monitoring: Monitor endpoint logs for suspicious browser activity, such as unexpected child processes spawned by the Chrome executable or unusual outbound network connections initiated by the browser.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious payloads or suspicious script execution originating from browser processes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise and the critical CVSS severity rating, organizations must treat this update with high urgency. Administrators should prioritize the deployment of the patched version of Google Chrome to all workstations to mitigate the risk of remote code execution and maintain a secure operating environment.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources