CVE-2026-87650

9.6

Google · Chrome

An out of bounds read vulnerability in the WebGL component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.

Executive summary

A critical out of bounds read vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox, posing a severe risk to end user systems.

Vulnerability

This vulnerability is an out of bounds read (CWE-125) located in the WebGL implementation of the browser. It allows an unauthenticated remote attacker to trigger memory corruption and achieve arbitrary code execution by enticing a user to visit a malicious HTML page.

Business impact

The potential for arbitrary code execution outside the browser sandbox represents a critical security failure, as it allows attackers to bypass core security controls and gain control over the underlying host. Given the CVSS score of 9.6, this vulnerability carries a high probability of total system compromise, which could lead to data exfiltration, the installation of persistent malware, or lateral movement within the corporate network.

Remediation

Immediate Action: Update all Google Chrome instances to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patches.

Proactive Monitoring: Review web proxy and endpoint detection logs for unusual traffic patterns or browser crashes associated with WebGL rendering, which may indicate attempted exploitation.

Compensating Controls: Ensure that enterprise browser policies are configured to disable unnecessary features and that users are restricted from executing untrusted scripts if possible.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability is classified as critical due to the potential for remote code execution via common web browsing activities. Organizations must prioritize the deployment of the browser update across all workstations and servers to eliminate this risk. Failure to patch promptly leaves the infrastructure vulnerable to exploitation through standard web-based attack vectors.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources