CVE-2026-87554

Google · Chrome

A race condition in the Chromoting component of Google Chrome on Windows allows a local attacker to execute arbitrary code outside of the browser sandbox.

Executive summary

A high-severity race condition in Google Chrome for Windows allows local attackers to escape the sandbox and execute arbitrary code, necessitating an immediate update to version 153.0.8010.36.

Vulnerability

The vulnerability is a race condition (CWE-367) within the Chromoting feature. It allows an unauthenticated local attacker to leverage a local program to achieve sandbox escape and subsequent arbitrary code execution.

Business impact

The ability for a local attacker to break out of the browser sandbox poses a significant risk to system integrity and confidentiality. Given the CVSS score of 8.1, this flaw could be exploited to gain elevated control over the host operating system, potentially leading to full system compromise, lateral movement within the network, or the theft of sensitive user data stored on the machine.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately across all Windows endpoints.

Proactive Monitoring: Monitor endpoint security logs for signs of unusual local process execution or unauthorized attempts to access system-level resources by the Chrome browser process.

Compensating Controls: Ensure that Endpoint Detection and Response (EDR) solutions are configured to monitor for anomalous sandbox escapes and utilize local access controls to limit the privileges of standard users on shared workstations.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the deployment of the 153.0.8010.36 update to all Windows-based assets as part of their standard patch management cycle. Because this vulnerability allows for complete sandbox escape, delaying the update increases the window of opportunity for local malicious actors or malware residing on the system to escalate their privileges.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.1 (3.1)
  4. Analyst report written

Sources