CVE-2026-87588

8.8

Google · Chrome

A use after free vulnerability in the Chromecast component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code on user systems through malicious web content.

Vulnerability

This is a use after free vulnerability (CWE-416) occurring within the Chromecast component. The flaw allows an unauthenticated remote attacker to gain code execution within the browser sandbox by enticing a user to navigate to a specially crafted HTML page.

Business impact

Successful exploitation of this vulnerability results in arbitrary code execution within the browser sandbox, which can lead to full compromise of the user session, data theft, or further lateral movement within the network. Given the CVSS score of 8.8, this vulnerability is classified as High severity due to the potential for complete loss of confidentiality, integrity, and availability of the affected browser environment.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor browser-related crash logs and security telemetry for unusual process behavior or unexpected sandbox escapes.

Compensating Controls: Ensure that endpoint protection software is active and that users are instructed to avoid interacting with untrusted or suspicious web links.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations must prioritize the deployment of the 153.0.8010.36 update across all workstations and browser environments. Because this vulnerability involves remote code execution through standard web navigation, the risk to end-users is significant and warrants immediate patching to prevent potential exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources