CVE-2026-87638
9.6Google · Chrome
An out of bounds write vulnerability in the Google Chrome Media component allows a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
A critical out of bounds write vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code on the host system.
Vulnerability
This vulnerability involves an out of bounds write in the Media component, which can be triggered by an unauthenticated remote attacker through a specially crafted HTML page. The flaw allows for potential code execution outside of the browser sandbox.
Business impact
The CVSS score of 9.6 reflects the extreme severity of this flaw, as it facilitates remote code execution which could lead to full system compromise. Successful exploitation could result in the exfiltration of sensitive data, installation of malware, or unauthorized access to the underlying operating system, causing significant operational and reputational damage.
Remediation
Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution originating from the Chrome application.
Compensating Controls: Ensure that browser sandboxing features remain enabled and consider using endpoint protection software that can detect and block malicious memory write attempts.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the potential for remote code execution and the high CVSS severity score, this vulnerability poses a severe risk to organizational security. IT administrators must prioritize the deployment of the latest Chrome update across all managed workstations to remediate this flaw and prevent potential exploitation.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry