CVE-2026-87448
massUse-after-free in Google Chrome DevTools enables code execution outside sandbox
Google Chrome contains a use-after-free vulnerability (CWE-416) in its DevTools component that is triggered when a user loads a specially crafted HTML page. A successful exploit allows a remote attacker to execute arbitrary code outside the browser's sandbox, meaning code runs on the host rather than being confined to the renderer. The published CVSS 3.1 score is 9.6 (critical), although Google's own Chromium security severity rating is Low, and the attack requires user interaction (visiting attacker-controlled content). Users of Google Chrome versions prior to 153.0.8010.36 are affected; downstream Chromium-based browsers may inherit the issue but are not named in this advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later and restart the browser; verify the running version at chrome://version and ensure auto-updates are enabled across managed fleets. As an interim measure, restrict exposure to untrusted web content, and if you run Chromium-based derivatives, watch for equivalent updates from those vendors incorporating the same Chromium fix.
| google chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.