CVE-2026-87648

Google · Chrome

A use-after-free vulnerability in the ANGLE component of Google Chrome on Windows allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome on Windows allows remote attackers to execute arbitrary code by compromising the renderer process.

Vulnerability

This flaw is a use-after-free vulnerability located within the ANGLE graphics engine component. A remote, unauthenticated attacker can exploit this memory corruption issue by enticing a user to navigate to a specially crafted HTML page, leading to sandbox escape and potential arbitrary code execution.

Business impact

The ability for an attacker to escape the browser sandbox and execute arbitrary code poses a severe threat to endpoint integrity. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, and the installation of persistent malicious software. Given the CVSS score of 8.3, this vulnerability represents a significant risk to organizational security posture and requires prioritized remediation.

Remediation

Immediate Action: Update all instances of Google Chrome on Windows to version 153.0.8010.36 or later to incorporate the vendor-supplied security patch.

Proactive Monitoring: Monitor endpoint detection and response logs for unusual browser child process behavior or unexpected attempts to access protected system memory.

Compensating Controls: Ensure that browser-based security features, such as site isolation, remain enabled and verify that endpoint security software is configured to block malicious script execution.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the potential for arbitrary code execution and sandbox escape, organizations should treat this vulnerability with high urgency. Administrators must prioritize the deployment of the 153.0.8010.36 update across the enterprise to mitigate the risk of remote exploitation. Failure to patch promptly leaves user workstations vulnerable to sophisticated browser-based attacks.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.3 (3.1)
  4. Analyst report written

Sources