CVE-2026-87587
8.8Google · Chrome
A use after free vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome could allow a remote attacker to achieve arbitrary code execution through a malicious webpage.
Vulnerability
This flaw involves a use after free error within the V8 JavaScript engine. It requires no authentication to trigger, though it does necessitate user interaction by convincing a victim to navigate to a specifically crafted HTML page.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code within the context of the browser sandbox. Given the CVSS score of 8.8, the potential for full compromise of user data and system integrity is significant, presenting a high risk to organizational security and data confidentiality.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later to apply the necessary security patches.
Proactive Monitoring: Review web proxy logs and endpoint security telemetry for traffic patterns associated with suspicious or anomalous HTML content rendering.
Compensating Controls: Deploy endpoint protection solutions capable of detecting and blocking malicious browser activity and ensure that browser-based security policies are strictly enforced.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the ubiquity of Google Chrome, necessitates an immediate patching cycle across all enterprise workstations. IT administrators should prioritize the deployment of version 153.0.8010.36 to eliminate the risk of arbitrary code execution and ensure browser stability.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section