CVE-2026-87612
8.8Google · Chrome
A type confusion vulnerability in the V8 JavaScript engine of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a specially crafted HTML page.
Executive summary
A critical type confusion vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution, necessitating an immediate update to version 153.0.8010.36 or later.
Vulnerability
This vulnerability involves a type confusion flaw within the V8 engine, which is triggered when a user visits a malicious website. An unauthenticated attacker can exploit this to execute arbitrary code within the browser sandbox.
Business impact
Successful exploitation of this flaw enables an attacker to execute arbitrary code on the host system, which could lead to full system compromise or data exfiltration. Given the CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it allows attackers to bypass standard security boundaries and potentially gain persistence on the victim's device.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or newer immediately to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected network traffic originating from the browser process.
Compensating Controls: Ensure that browser-based security policies, such as site isolation and strict content security policies, are enforced to limit the potential impact of successful exploitation.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
The severity of this vulnerability, combined with its potential for arbitrary code execution, mandates a rapid deployment of the provided vendor patch. Organizations should prioritize updating their browser fleet to ensure protection against this flaw and prevent potential compromise of internal assets.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Analyst report written
- Published in the daily brief high section