AI analysis
CVE-2026-87444 is a memory-corruption vulnerability (CWE-119) in the codecs component of Google Chrome, rated High severity by Chromium and fixed in Chrome 153.0.8010.36 as part of a release containing roughly 230 security fixes. A remote attacker can trigger the bug by luring a user to open a crafted HTML page, with the CVSS vector requiring user interaction but no privileges. Successful exploitation yields arbitrary code execution inside the browser's sandbox, meaning attacker code runs with the renderer's restricted privileges rather than taking over the entire device. Any user running Chrome prior to 153.0.8010.36 is affected, which at the time of disclosure effectively spans Chrome's multi-billion-user installed base until auto-updates land. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS is low (~0.4%); related reporting on the Chrome 153 release mentions a zero-day exploited in the wild, but the CVE description does not confirm that this specific flaw is the one being actively exploited.
What to do: Update Chrome to 153.0.8010.36 or later immediately (verify via chrome://settings/help) and force the update across managed fleets using enterprise browser-management policies. Because exploitation requires user interaction, remind users to avoid opening HTML pages or links from untrusted sources as an interim mitigation. Administrators should inventory endpoints for Chrome versions below 153.0.8010.36 and confirm remediation.
Affected
| google chrome | prior to 153.0.8010.36 |
Estimated exposure
mass≈3+ billion users (Chrome's global installed base on versions prior to 153.0.8010.36) — Chrome is the world's dominant desktop browser with a multi-billion-user installed base, and every installation running a version before 153.0.8010.36 is exposed until Chrome's automatic updater delivers the patch.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.