CVE-2026-87621
9.6Google · Chrome
An out of bounds write vulnerability in the ANGLE graphics engine of Google Chrome for Windows allows unauthenticated remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical out of bounds write vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution on Windows systems.
Vulnerability
This vulnerability resides in the ANGLE graphics component, where an out of bounds write flaw can be triggered by a remote, unauthenticated attacker through a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code outside the browser sandbox.
Business impact
The ability to execute arbitrary code outside the browser sandbox poses a severe threat to organizational security, as it grants attackers a foothold on the underlying operating system. Given the CVSS score of 9.6, this vulnerability represents a critical risk that could lead to full system compromise, data exfiltration, or the deployment of persistent malware within the corporate environment.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for anomalous browser behavior or unexpected process execution originating from the Chrome application.
Compensating Controls: Ensure that browser-based security policies are enforced and utilize endpoint detection and response tools to identify and block suspicious shellcode execution attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is highly critical due to its potential for sandbox escape and arbitrary code execution. Organizations should prioritize the deployment of the Chrome update across all Windows workstations to mitigate the risk of remote exploitation. Failure to patch this flaw leaves systems exposed to potential compromise by unauthenticated actors.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry