CVE-2026-87613
Google · Chrome
Google Chrome contains an incorrect reference resolution vulnerability in Extensions that allows a remote attacker to achieve sandbox escape and arbitrary code execution via crafted network traffic.
Executive summary
A critical remote code execution vulnerability in Google Chrome allows unauthenticated attackers to escape the browser sandbox and execute arbitrary code via malicious network traffic.
Vulnerability
The flaw, categorized as CWE-706, involves incorrect reference resolution within the Extensions component. An unauthenticated remote attacker can trigger this vulnerability by sending crafted network traffic to the browser, leading to code execution outside the security sandbox.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational security, as it facilitates full system compromise by bypassing Chrome's sandbox protections. Given the CVSS score of 9.0, this issue is classified as critical, threatening data confidentiality, integrity, and availability for any workstation running the affected software.
Remediation
Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to apply the necessary security fixes.
Proactive Monitoring: Monitor network traffic for unusual patterns or spikes in malformed packets directed toward endpoints, and review browser error logs for signs of anomalous extension behavior.
Compensating Controls: Utilize endpoint detection and response tools to identify unauthorized processes spawned by the browser, and ensure that network-level defenses are configured to block suspicious or non-standard traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The potential for remote code execution outside the browser sandbox makes this vulnerability a high priority for remediation. Security teams must ensure that all enterprise deployments of Google Chrome are updated to the fixed version without delay to prevent potential exploitation.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.0 (3.1)
- Analyst report written