ZeroHour

CVE-2026-87440

mass

Out-of-Bounds Read in Google Chrome Media Component Enables Sandboxed Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-87440 is an out-of-bounds read (CWE-125) in the Media component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker can trigger the flaw by convincing a user to open a specially crafted HTML page, for example via a malicious website or link. Successful exploitation allows the attacker to execute arbitrary code inside the Chrome renderer sandbox, with high impact on confidentiality, integrity, and availability per the assigned CVSS 8.8 score. Users of Google Chrome on any platform running a version prior to 153.0.8010.36 are affected. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.4%, indicating no confirmed in-the-wild exploitation at this time.

What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints, and verify the running version at chrome://version; for fleets, enforce the update via enterprise browser-management policies. As the attack requires user interaction with a crafted HTML page, reinforce safe-linking and phishing awareness while patching. Also check whether any Chromium-derived browsers in your environment track the same Media codebase and apply vendor updates when available.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global install base; all stable-channel installs below 153.0.8010.36) — Chrome is the world's dominant browser with a multi-billion-user install base, and the vulnerable range covers every release before the 153.0.8010.36 fix, so exposure is effectively the entire pre-patch Chrome population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.