CVE-2026-87625

8.8

Google · Chrome

A use after free vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted extension.

Executive summary

A high-severity use after free vulnerability in Google Chrome version 153.0.8010.36 and earlier poses a significant risk of remote code execution if a user is successfully socially engineered.

Vulnerability

The vulnerability is a use after free flaw (CWE-416) within the V8 JavaScript engine. A remote, unauthenticated attacker can exploit this condition by leveraging social engineering to trick a user into installing or interacting with a malicious Chrome extension, leading to arbitrary code execution within the browser sandbox.

Business impact

The potential for arbitrary code execution within the browser environment presents a severe security risk, as it could lead to full system compromise if the sandbox is further bypassed or lead to the theft of sensitive user data, credentials, and session tokens. With a CVSS score of 8.8, this vulnerability represents a high-risk scenario that could result in significant operational disruption and data loss. Organizations relying on Chrome for business-critical web applications must prioritize this update to prevent potential exploitation.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or the unauthorized installation of browser extensions across the corporate environment.

Compensating Controls: Implement strict browser policies via Group Policy or MDM solutions to restrict the installation of extensions to only those explicitly approved by the organization.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution and the high CVSS score, this update is critical for maintaining browser security. Administrators should verify that all endpoints have successfully updated to version 153.0.8010.36 or later and investigate any systems found running older versions as a high priority.

More Google CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources