CVE-2026-87637
9.6Google · Chrome
A use after free vulnerability in Google Chrome Extensions on Mac allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution outside the browser sandbox.
Vulnerability
The flaw is a use after free vulnerability (CWE-416) within the browser Extensions component. An unauthenticated remote attacker can trigger this condition by enticing a user to visit a specially crafted HTML page, leading to sandbox escape and arbitrary code execution.
Business impact
The potential for remote code execution outside the sandbox presents a severe risk to organizational security, as it allows attackers to bypass core browser protections. Given the high CVSS score of 9.6, this vulnerability could lead to total system compromise, data theft, and the installation of persistent malware on affected workstations.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected process spawns originating from the Chrome application.
Compensating Controls: Ensure that browser-based security policies are enforced and consider using endpoint detection and response (EDR) solutions to identify and block suspicious child processes initiated by the browser.
Exploitation status
Public Exploit Available: No — there is no evidence of a weaponized public exploit or published proof-of-concept in the provided data.
Analyst recommendation
This vulnerability is classified as critical due to the potential for arbitrary code execution and sandbox escape. IT administrators should prioritize the deployment of the 153.0.8010.36 update across all Mac environments to eliminate this exposure. Failure to patch promptly leaves end-user systems vulnerable to remote compromise via standard web browsing activities.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry