CVE-2026-87604
Google · Chrome
An out of bounds read vulnerability in the ANGLE graphics component of Google Chrome allows remote attackers to potentially execute arbitrary code outside the browser sandbox.
Executive summary
Google Chrome versions prior to 153.0.8010.36 are vulnerable to an out of bounds read flaw that could allow remote code execution if a user visits a specially crafted webpage.
Vulnerability
This vulnerability involves an out of bounds read within the ANGLE graphics library. An unauthenticated remote attacker can exploit this via a crafted HTML page to trigger memory corruption and achieve code execution outside the browser sandbox context.
Business impact
Successful exploitation of this flaw poses a significant risk to organizational endpoints, as it allows attackers to break out of the browser sandbox and execute arbitrary code on the underlying host system. Given the CVSS score of 8.3, this represents a high severity risk that could lead to full system compromise, data exfiltration, or the deployment of further malicious payloads.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual browser process behavior or unexpected child process spawning events that may indicate sandbox escape attempts.
Compensating Controls: Ensure that enterprise browser policies are configured to disable unnecessary features and that users operate with the principle of least privilege to limit the impact of a potential compromise.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability highlights the critical nature of maintaining up to date web browsers to prevent sandbox escapes. Security teams should prioritize the deployment of the Chrome 153.0.8010.36 update across the fleet to neutralize this code execution risk and ensure continued protection against potential browser based attacks.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.3 (3.1)
- Analyst report written