CVE-2026-87634

9.6

Google · Chrome

A use after free vulnerability in the WebPackaging component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a severe risk to system integrity and data confidentiality.

Vulnerability

This is a use after free vulnerability (CWE-416) occurring in the WebPackaging component. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution outside the browser sandbox.

Business impact

Successful exploitation of this vulnerability allows for full system compromise, as an attacker can execute arbitrary code with the privileges of the logged-in user. Given the CVSS score of 9.6, this represents a critical risk to business operations, as it could lead to unauthorized data access, the installation of malware, or complete system takeover.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to resolve this vulnerability.

Proactive Monitoring: Monitor endpoint security logs for signs of suspicious browser behavior or unauthorized process execution originating from the Chrome application.

Compensating Controls: Ensure that browser-based security features are enabled and utilize endpoint protection platforms to detect and block malicious web content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with its potential for arbitrary code execution, necessitates immediate action. Administrators must prioritize the deployment of the browser update across all workstations to mitigate the risk of remote exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources