CVE-2026-87644
Google · Chrome
An incorrect authorization flaw in the Views component of Google Chrome on Windows allows a remote attacker to execute arbitrary code outside the browser sandbox via social engineering.
Executive summary
A high-severity authorization vulnerability in Google Chrome for Windows could allow remote attackers to escape the browser sandbox and execute arbitrary code on the underlying system.
Vulnerability
This vulnerability, categorized as CWE-863, involves incorrect authorization within the Views component. An unauthenticated attacker can exploit this flaw by compromising the renderer process and leveraging social engineering to execute arbitrary code outside the browser sandbox.
Business impact
The potential for sandbox escape and arbitrary code execution poses a severe risk to corporate endpoints. A successful exploit could lead to full system compromise, unauthorized access to sensitive user data, and the potential for lateral movement within the network. With a CVSS score of 8.3, this vulnerability represents a significant threat to organizational security posture.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected browser-initiated system calls that may indicate a sandbox escape attempt.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block suspicious renderer process behavior, and ensure that users are trained to recognize social engineering tactics.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote code execution and the bypass of critical browser security boundaries, organizations must prioritize the deployment of the 153.0.8010.36 update. Failure to remediate this vulnerability leaves systems exposed to sophisticated attacks that could result in total system compromise. Update all instances of Google Chrome on Windows environments immediately.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.3 (3.1)
- Analyst report written