CVE-2026-87646

9.6

Google · Chrome

A use-after-free vulnerability in the Web Authentication component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use-after-free vulnerability in Google Chrome enables remote code execution, posing a severe risk to system integrity and user data privacy.

Vulnerability

This is a use-after-free flaw within the Web Authentication module of Google Chrome. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to navigate to a specifically crafted HTML page, leading to arbitrary code execution outside the browser sandbox.

Business impact

The ability for an attacker to achieve remote code execution (RCE) via a web browser represents a significant threat to the organization. Given the CVSS score of 9.6, this vulnerability carries a critical severity, as successful exploitation could lead to total system compromise, unauthorized access to sensitive corporate data, and the potential for lateral movement within the network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor browser-related crash logs and security event logs for abnormal patterns that might indicate attempts to trigger memory corruption or illegal memory access.

Compensating Controls: While browser-level patches are the only definitive fix, ensure that endpoint protection platforms are active and that users are restricted from executing untrusted scripts if possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability is classified as critical due to the potential for complete system compromise through standard web browsing activities. Security teams must prioritize the deployment of the browser update across all workstations and servers to mitigate the risk of remote code execution. Immediate patching is the only effective way to neutralize this threat.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources