CVE-2026-87440
massOut-of-Bounds Read in Google Chrome Media Component Enables Sandboxed Code Execution
CVE-2026-87440 is an out-of-bounds read (CWE-125) in the Media component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker can trigger the flaw by convincing a user to open a specially crafted HTML page, for example via a malicious website or link. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome renderer sandbox, with high impact on confidentiality, integrity, and availability per the assigned CVSS 8.8 score. Users of Google Chrome on any platform running a version prior to 153.0.8010.36 are affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.4%, indicating no confirmed in-the-wild exploitation at this time.
What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, and verify the running version at chrome://version; for fleets, enforce the update via enterprise browser-management policies. As the attack requires user interaction with a crafted HTML page, reinforce safe-linking and phishing awareness while patching. Also check whether any Chromium-derived browsers in your environment track the same Media codebase and apply vendor updates when available.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.