CVE-2026-87617

8.8

Google · Chrome

A use-after-free vulnerability in the Google Chrome DevTools component allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page and social engineering.

Executive summary

Google Chrome versions prior to 153.0.8010.36 are vulnerable to a use-after-free flaw that could lead to arbitrary code execution when a user is tricked into visiting a malicious site.

Vulnerability

This is a use-after-free vulnerability (CWE-416) located in the DevTools component of Google Chrome. The flaw allows an unauthenticated remote attacker to execute arbitrary code within the browser sandbox if a victim is successfully lured into interacting with a crafted HTML page.

Business impact

Successful exploitation of this vulnerability results in arbitrary code execution, which grants an attacker the ability to compromise the integrity and confidentiality of the user session. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise if the sandbox is bypassed or if additional vulnerabilities are chained.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to incorporate the provided security fix.

Proactive Monitoring: Monitor endpoint logs for suspicious browser activity or unconventional DevTools usage patterns that may indicate an attempt to trigger memory corruption errors.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web traffic and utilize browser-based security policies to restrict unauthorized access to sensitive browser features.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the high severity of this vulnerability, organizations must prioritize patching their Google Chrome installations. While social engineering is a prerequisite for exploitation, the risk of code execution necessitates prompt remediation to prevent potential system compromise and data loss.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources