CVE-2026-87601

Google · Chrome

A race condition in the V8 engine of Google Chrome allows a remote attacker to achieve arbitrary code execution within the browser sandbox via a specially crafted HTML page.

Executive summary

A critical race condition in Google Chrome could allow a remote attacker to execute arbitrary code within the browser sandbox, necessitating an immediate update to version 153.0.8010.36 or later.

Vulnerability

This vulnerability is a race condition (CWE-362) within the V8 JavaScript engine. It requires no authentication and relies on user interaction, such as navigating to a malicious website, to trigger the flaw.

Business impact

The ability for a remote attacker to execute arbitrary code within the Chrome sandbox presents a significant risk to organizational endpoints. Successful exploitation could lead to full compromise of the browser session, potentially resulting in data theft, credential harvesting, or further lateral movement into the local system. Despite the vendor classifying the Chromium severity as low, the CVSS score of 7.5 indicates a high risk that requires prioritized attention.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary security patches.

Proactive Monitoring: Review browser-based security logs for anomalous navigation patterns or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious script execution within browser processes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the capability for arbitrary code execution, this vulnerability poses a substantial threat to workstation security. Organizations should ensure that automatic updates are enabled or push the update to version 153.0.8010.36 across their fleet without delay to mitigate the risk of compromise.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources