CVE-2026-87618

Google · Chrome

A vulnerability in Google Chrome on Windows allows an attacker who has compromised the renderer process to escape the sandbox and execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity sandbox escape vulnerability in Google Chrome allows remote attackers to execute arbitrary code, necessitating an immediate update to version 153.0.8010.36 or later.

Vulnerability

The flaw stems from incorrect reference resolution within the Storage component. An unauthenticated remote attacker can exploit this via a specially crafted HTML page, provided they have already compromised the renderer process, to achieve arbitrary code execution outside the browser sandbox.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational endpoints, as it enables attackers to break out of the browser sandbox and execute code with the privileges of the user. Given the CVSS score of 8.3, this flaw represents a significant threat to system integrity and confidentiality, potentially leading to full system compromise or the installation of persistent malware.

Remediation

Immediate Action: Update all Google Chrome instances on Windows to version 153.0.8010.36 or later immediately to apply the necessary security patches.

Proactive Monitoring: Review endpoint security logs for anomalous process behavior or unauthorized child processes spawned by the Chrome renderer.

Compensating Controls: Ensure that endpoint protection platforms are active and configured to detect and block suspicious code execution attempts originating from web browser processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical path to system compromise for desktop users. Security teams should prioritize the deployment of the browser update across all managed Windows assets to ensure the sandbox protection remains intact and to mitigate the risk of remote code execution.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources