CVE-2026-87633

Google · Chrome

A use-after-free vulnerability in the Views component of Google Chrome allows a local attacker to achieve arbitrary code execution outside the browser sandbox via UI interaction.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome allows local attackers to execute arbitrary code, posing a significant risk to endpoint integrity.

Vulnerability

This vulnerability is a use-after-free flaw (CWE-416) within the Views component of the browser. It allows a local attacker to bypass sandbox protections and execute arbitrary code through specific UI interactions.

Business impact

The ability for an attacker to execute arbitrary code outside the browser sandbox represents a critical breach of the security boundary, potentially granting an attacker full control over the local system. With a CVSS score of 8.6, this flaw carries a high impact on system confidentiality, integrity, and availability. Compromise of this nature could lead to lateral movement within the network, theft of sensitive credentials, or the deployment of persistent malware.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or attempts to interact with browser UI components that deviate from standard user behavior.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect unauthorized code execution or memory exploitation attempts.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for sandbox escape and subsequent code execution, this vulnerability poses an unacceptable risk to enterprise workstations. IT administrators should prioritize the deployment of the 153.0.8010.36 update across all managed devices. Regular browser patching is essential to maintaining the security boundary between web content and the host operating system.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.6 (3.1)
  4. Analyst report written

Sources