CVE-2026-87636
8.8Google · Chrome
A type confusion vulnerability in the XML processing component of Google Chrome allows remote attackers to execute arbitrary code via a malicious HTML page.
Executive summary
Google Chrome versions prior to 153.0.8010.36 are vulnerable to a type confusion flaw that could allow a remote attacker to execute arbitrary code within the browser sandbox.
Vulnerability
This is a type confusion vulnerability (CWE-843) located in the XML parsing logic of the browser. The attack vector is unauthenticated and requires user interaction, as the victim must visit a specially crafted HTML page to trigger the execution.
Business impact
The exploitation of this vulnerability could lead to arbitrary code execution within the sandbox, potentially resulting in complete compromise of the browser session. With a CVSS score of 8.8, this represents a high severity risk that could lead to unauthorized data access, session hijacking, or the installation of malicious software on the host system.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected child process spawning associated with the Chrome executable.
Compensating Controls: Ensure that browser-based security features, such as site isolation and sandboxing, are fully enabled and not bypassed by group policy or custom configurations.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit or proof-of-concept available at this time.
Analyst recommendation
Given the high CVSS score and the potential for arbitrary code execution, organizations should prioritize updating their browser fleet immediately. While the requirement for user interaction provides a slight barrier, the risk of drive-by attacks via malicious websites remains significant, necessitating prompt deployment of the Chrome 153.0.8010.36 update.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section