CVE-2026-87558

9.6

Google · Chrome

A use-after-free vulnerability in the Payments component of Google Chrome on Mac allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use-after-free vulnerability in Google Chrome for Mac could allow a remote attacker to achieve arbitrary code execution outside the browser sandbox.

Vulnerability

This is a use-after-free vulnerability (CWE-416) within the Payments component of the browser. It allows an unauthenticated remote attacker to gain control by enticing a user to navigate to a specifically crafted HTML page.

Business impact

The ability to execute arbitrary code outside the browser sandbox poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent malware. Given the CVSS score of 9.6, this vulnerability represents a critical threat that must be addressed immediately to prevent potential host-level exploitation.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately across all managed Mac endpoints.

Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected process execution patterns originating from the Chrome application.

Compensating Controls: Ensure that endpoint detection and response tools are active to monitor for abnormal child processes spawned by the browser, which may indicate exploit attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this flaw cannot be overstated, as it bypasses critical browser security boundaries. Administrators must prioritize the deployment of the 153.0.8010.36 update to all Mac users to mitigate the risk of remote code execution and potential system-wide compromise.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources