ZeroHour

CVE-2026-87444

mass

Memory Corruption in Google Chrome Codecs Allows Sandboxed Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-87444 is a memory-corruption vulnerability (CWE-119) in the codecs component of Google Chrome, rated High severity by Chromium and fixed in Chrome 153.0.8010.36 as part of a release containing roughly 230 security fixes. A remote attacker can trigger the bug by luring a user to open a crafted HTML page, with the CVSS vector requiring user interaction but no privileges. Successful exploitation yields arbitrary code execution inside the browser's sandbox, meaning attacker code runs with the renderer's restricted privileges rather than taking over the entire device. Any user running Chrome prior to 153.0.8010.36 is affected, which at the time of disclosure effectively spans Chrome's multi-billion-user installed base until auto-updates land. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS is low (~0.4%); related reporting on the Chrome 153 release mentions a zero-day exploited in the wild, but the CVE description does not confirm that this specific flaw is the one being actively exploited.

What to do: Update Chrome to 153.0.8010.36 or later immediately (verify via chrome://settings/help) and force the update across managed fleets using enterprise browser-management policies. Because exploitation requires user interaction, remind users to avoid opening HTML pages or links from untrusted sources as an interim mitigation. Administrators should inventory endpoints for Chrome versions below 153.0.8010.36 and confirm remediation.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global installed base on versions prior to 153.0.8010.36) — Chrome is the world's dominant desktop browser with a multi-billion-user installed base, and every installation running a version before 153.0.8010.36 is exposed until Chrome's automatic updater delivers the patch.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Memory corruption in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs