CVE-2026-87654

9.6

Google · Chrome

A buffer overflow vulnerability in the ANGLE graphics component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical buffer overflow vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox, posing a severe risk of system compromise.

Vulnerability

The flaw exists within the ANGLE graphics library, where a buffer overflow can be triggered by a specially crafted HTML page. This is an unauthenticated remote code execution vulnerability that impacts users on the Windows platform.

Business impact

Successful exploitation of this vulnerability allows an attacker to escape the browser sandbox and execute arbitrary code on the underlying host system. Given the CVSS score of 9.6, this represents a critical risk that could lead to complete system takeover, unauthorized access to sensitive local data, and potential lateral movement within the corporate network.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.36 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected child process spawning originating from the Chrome application.

Compensating Controls: While no direct virtual patch exists for this memory corruption issue, ensure that browser-based security policies and endpoint protection software are configured to block suspicious external content and restrict execution privileges.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents an extreme risk to organizational security due to the potential for full system compromise. Security teams should prioritize the deployment of the Chrome update across all Windows workstations to neutralize this threat. Delaying the application of this patch leaves systems exposed to potential remote code execution attacks.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources