CVE-2026-87618
Google · Chrome
A vulnerability in Google Chrome on Windows allows an attacker who has compromised the renderer process to escape the sandbox and execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity sandbox escape vulnerability in Google Chrome allows remote attackers to execute arbitrary code, necessitating an immediate update to version 153.0.8010.36 or later.
Vulnerability
The flaw stems from incorrect reference resolution within the Storage component. An unauthenticated remote attacker can exploit this via a specially crafted HTML page, provided they have already compromised the renderer process, to achieve arbitrary code execution outside the browser sandbox.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational endpoints, as it enables attackers to break out of the browser sandbox and execute code with the privileges of the user. Given the CVSS score of 8.3, this flaw represents a significant threat to system integrity and confidentiality, potentially leading to full system compromise or the installation of persistent malware.
Remediation
Immediate Action: Update all Google Chrome instances on Windows to version 153.0.8010.36 or later immediately to apply the necessary security patches.
Proactive Monitoring: Review endpoint security logs for anomalous process behavior or unauthorized child processes spawned by the Chrome renderer.
Compensating Controls: Ensure that endpoint protection platforms are active and configured to detect and block suspicious code execution attempts originating from web browser processes.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical path to system compromise for desktop users. Security teams should prioritize the deployment of the browser update across all managed Windows assets to ensure the sandbox protection remains intact and to mitigate the risk of remote code execution.
More Google CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.3 (3.1)
- Analyst report written