CVE-2026-87579
8.8Google · Chrome
A buffer overflow vulnerability in the WebRTC component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical buffer overflow vulnerability in Google Chrome allows remote code execution, posing a significant threat to user system integrity.
Vulnerability
This flaw is a buffer overflow (CWE-122) located in the WebRTC component of Google Chrome. It can be triggered by an unauthenticated remote attacker who lures a user to a specially crafted HTML page, leading to arbitrary code execution within the browser sandbox.
Business impact
The ability for a remote attacker to execute arbitrary code on end-user machines carries a high risk of system compromise, data theft, and potential malware installation. With a CVSS score of 8.8, this vulnerability is classified as High severity, as it allows attackers to bypass security boundaries and gain control over the browser environment. Organizations should prioritize patching to prevent potential unauthorized access to sensitive corporate information.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-provided security patch.
Proactive Monitoring: Review endpoint security logs for unusual browser processes or unauthorized execution patterns originating from web-based traffic.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block suspicious shellcode execution patterns, and utilize browser-level policies to restrict WebRTC functionality if necessary.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution, this vulnerability represents a significant risk to organizational endpoints. Security teams must ensure that all browser installations are updated to version 153.0.8010.36 without delay. Automated patch management workflows should be validated to ensure the update reaches all workstations, thereby closing the attack vector before any potential exploits are developed in the wild.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section