CVE-2026-87572

Google · Chrome

A high-severity injection vulnerability in Google Chrome DevTools allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 153.0.8010.36 are vulnerable to a sandbox escape via DevTools, which could allow remote attackers to execute arbitrary code on the host system.

Vulnerability

This is an injection flaw (CWE-74) within the DevTools component of Google Chrome. The vulnerability allows an attacker who has already compromised the renderer process to escape the sandbox and execute code with higher privileges upon the user interacting with a crafted HTML page.

Business impact

The potential for arbitrary code execution outside the browser sandbox presents a severe risk to organizational assets. A successful exploit could lead to full system compromise, unauthorized data exfiltration, and lateral movement within the network. With a CVSS score of 8.3, this vulnerability is classified as High, reflecting the significant impact on confidentiality, integrity, and availability of the affected workstation.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later across all managed endpoints to apply the necessary security patches.

Proactive Monitoring: Security teams should monitor endpoint security logs for unusual process execution patterns or unexpected child processes originating from the Chrome browser.

Compensating Controls: Ensure that the browser sandbox remains fully enabled and apply group policies to restrict the execution of untrusted external content where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of potential sandbox escapes, organizations must prioritize the deployment of the browser update to all users. Relying on browser-level security without maintaining the latest patch level leaves systems exposed to sophisticated threats that bypass standard browser protections. Apply the update immediately to ensure the integrity of the browser sandbox.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources