CVE-2026-87628

Google · Chrome

A use after free vulnerability in Google Chrome's Cast component allows an adjacent attacker to achieve arbitrary code execution outside the browser sandbox via crafted network traffic.

Executive summary

A critical use after free vulnerability in Google Chrome allows adjacent attackers to execute arbitrary code, necessitating an immediate update to version 153.0.8010.36 or later.

Vulnerability

This vulnerability is a use after free condition (CWE-416) located within the Cast component. It allows an unauthenticated adjacent attacker to potentially execute arbitrary code outside the browser sandbox by transmitting crafted network packets.

Business impact

The ability to execute arbitrary code outside the browser sandbox poses a severe threat to workstation integrity and organizational security. An attacker on the local network could gain persistent access to the host system, leading to data exfiltration or lateral movement. While the CVSS score of 8.3 reflects a High severity, the impact on system integrity and the potential for sandbox escape warrant immediate remediation.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later to apply the necessary security patches.

Proactive Monitoring: Review network traffic logs for anomalous patterns originating from local network segments, specifically focusing on unexpected Cast-related protocol activity.

Compensating Controls: Restrict local network access for untrusted devices and utilize endpoint detection and response tools to monitor for suspicious process spawns originating from the browser application.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for remote code execution and sandbox escape, organizations must prioritize updating Google Chrome across all endpoints. While there is no current evidence of exploitation in the wild, the technical nature of this flaw presents a significant risk to internal network security. Ensure that automatic updates are enabled and verify compliance across the enterprise immediately.

More Google CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources