CVE-2026-87609
Google · Chrome
A use-after-free vulnerability in the Sharing component of Google Chrome for iOS allows remote attackers to execute arbitrary code outside the sandbox via crafted network traffic.
Executive summary
A critical use-after-free vulnerability in Google Chrome for iOS enables remote code execution, posing a severe risk to device integrity and user data privacy.
Vulnerability
This is a use-after-free vulnerability (CWE-416) within the Sharing component of the browser. The flaw allows an unauthenticated remote attacker to trigger memory corruption and execute arbitrary code outside the browser sandbox by sending crafted network traffic to a victim.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute code with the permissions of the application, potentially leading to a complete compromise of the browser environment. Given the CVSS score of 9.6, this represents a critical risk that could result in unauthorized data exfiltration, persistent malware installation, or the bypass of essential security boundaries on the host device.
Remediation
Immediate Action: Update Google Chrome on all affected iOS devices to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Monitor network traffic for unusual patterns or spikes in malformed requests targeting mobile devices within the corporate environment.
Compensating Controls: Ensure that mobile device management policies are strictly enforced and consider utilizing network-level security tools to filter potentially malicious traffic originating from unknown or untrusted external sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical severity rating and the potential for remote code execution, organizations must prioritize the deployment of the provided security update across all managed iOS devices. Failure to patch this vulnerability leaves endpoints susceptible to remote compromise, and immediate action is required to maintain the security posture of the mobile fleet.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written