CVE-2026-87639

Google · Chrome

A use after free vulnerability in the WebPackaging component of Google Chrome allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows remote code execution, posing a significant risk to browser security and system integrity.

Vulnerability

This vulnerability is a use after free flaw in the WebPackaging component, which can be triggered by a remote, unauthenticated attacker using a specially crafted HTML page to compromise the renderer process and escape the sandbox.

Business impact

The ability to execute arbitrary code outside the browser sandbox represents a critical risk, as it allows attackers to bypass security boundaries, potentially leading to full system compromise, unauthorized data access, or the installation of malicious software. With a CVSS score of 8.3, this vulnerability is classified as high severity, and it necessitates immediate attention to prevent potential exploitation in enterprise environments.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected process execution patterns originating from the Google Chrome renderer.

Compensating Controls: Ensure that browser sandbox protections are fully enabled, and consider utilizing endpoint detection and response tools to identify and block suspicious shellcode execution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote code execution and sandbox escape, organizations must prioritize the deployment of the browser update across all workstations. Promptly patching this vulnerability is the most effective way to eliminate the risk of exploitation and maintain the security posture of the browser environment.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources