CVE-2026-87578

Google · Chrome

A use-after-free vulnerability in the Google Chrome Receiver component allows an adjacent attacker to achieve arbitrary code execution outside the sandbox using crafted network traffic.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome, designated CVE-2026-87578, allows adjacent attackers to execute arbitrary code and bypass sandbox protections.

Vulnerability

This is a use-after-free flaw (CWE-416) within the Receiver component of Google Chrome. An unauthenticated attacker located on the local network can trigger this vulnerability by sending crafted network traffic to the target system.

Business impact

The ability for an attacker to execute arbitrary code outside the browser sandbox poses a significant risk to organizational assets. Successful exploitation could lead to a complete system compromise, unauthorized data exfiltration, or the installation of persistent malicious software. Given the CVSS score of 8.3, this flaw is classified as high-severity and requires immediate attention to prevent lateral movement within the network.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review network traffic logs for anomalous patterns or unexpected traffic directed at browser-related ports, which may indicate attempted exploitation.

Compensating Controls: Implement network segmentation to isolate critical workstations from untrusted adjacent network segments, thereby limiting the reach of potential local network attackers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the 153.0.8010.36 update across all managed endpoints running Google Chrome. Because this vulnerability allows for code execution outside the sandbox, the risk to the underlying operating system is severe. Ensure that automated update mechanisms are functioning correctly to minimize the window of exposure.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources