CVE-2026-87613

Google · Chrome

Google Chrome contains an incorrect reference resolution vulnerability in Extensions that allows a remote attacker to achieve sandbox escape and arbitrary code execution via crafted network traffic.

Executive summary

A critical remote code execution vulnerability in Google Chrome allows unauthenticated attackers to escape the browser sandbox and execute arbitrary code via malicious network traffic.

Vulnerability

The flaw, categorized as CWE-706, involves incorrect reference resolution within the Extensions component. An unauthenticated remote attacker can trigger this vulnerability by sending crafted network traffic to the browser, leading to code execution outside the security sandbox.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it facilitates full system compromise by bypassing Chrome's sandbox protections. Given the CVSS score of 9.0, this issue is classified as critical, threatening data confidentiality, integrity, and availability for any workstation running the affected software.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to apply the necessary security fixes.

Proactive Monitoring: Monitor network traffic for unusual patterns or spikes in malformed packets directed toward endpoints, and review browser error logs for signs of anomalous extension behavior.

Compensating Controls: Utilize endpoint detection and response tools to identify unauthorized processes spawned by the browser, and ensure that network-level defenses are configured to block suspicious or non-standard traffic.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The potential for remote code execution outside the browser sandbox makes this vulnerability a high priority for remediation. Security teams must ensure that all enterprise deployments of Google Chrome are updated to the fixed version without delay to prevent potential exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.0 (3.1)
  4. Analyst report written

Sources