CVE-2026-87581
Google · Chrome
A use after free vulnerability in Google Chrome Payments allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
This is a use after free flaw within the Payments component of Google Chrome. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a malicious, crafted HTML page, which may lead to arbitrary code execution outside the browser sandbox.
Business impact
The potential for arbitrary code execution outside the sandbox constitutes a critical security failure, as it allows attackers to bypass standard browser protections. A successful exploit could result in full system compromise, unauthorized data access, or the deployment of persistent malware, justifying the 9.6 CVSS score.
Remediation
Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Monitor network traffic for unusual outbound connections or suspicious redirects from browser sessions that may indicate attempted exploitation.
Compensating Controls: Ensure that browser-based security policies, such as site isolation and sandboxing, remain enabled and are not bypassed by local configuration changes.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and its potential for sandbox escape, organizations must prioritize the deployment of the browser update across all endpoints. Users should be cautioned against interacting with untrusted or suspicious web content until the update is applied to prevent exploitation through social engineering.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written