CVE-2026-87607
9.6Google · Chrome
A use after free vulnerability in the Google Chrome Device component on Mac allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome for Mac enables remote attackers to execute arbitrary code, necessitating an immediate browser update.
Vulnerability
This is a use after free vulnerability located within the Device component of Google Chrome. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution outside the browser sandbox.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it could lead to full system compromise or unauthorized access to sensitive user data. With a CVSS score of 9.6, this vulnerability is classified as critical because it allows an attacker to escape the browser sandbox and perform malicious actions with the permissions of the local user.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately across all Mac endpoints.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected process execution patterns that may indicate a successful sandbox escape attempt.
Compensating Controls: Ensure that browser security settings are strictly enforced via mobile device management policies and encourage users to avoid navigating to untrusted or suspicious websites.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this vulnerability and the potential for remote code execution, organizations must prioritize the deployment of the patch. Failure to update Google Chrome leaves systems exposed to significant risk; therefore, security teams should treat this update with the highest urgency to ensure the continued integrity of their browser environments.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry