ZeroHour

CVE-2026-87448

mass

Use-after-free in Google Chrome DevTools enables code execution outside sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p41
Published
()
Modified
AI analysis

Google Chrome contains a use-after-free vulnerability (CWE-416) in its DevTools component that is triggered when a user loads a specially crafted HTML page. A successful exploit allows a remote attacker to execute arbitrary code outside the browser's sandbox, meaning code runs on the host rather than being confined to the renderer. The published CVSS 3.1 score is 9.6 (critical), although Google's own Chromium security severity rating is Low, and the attack requires user interaction (visiting attacker-controlled content). Users of Google Chrome versions prior to 153.0.8010.36 are affected; downstream Chromium-based browsers may inherit the issue but are not named in this advisory. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Update Google Chrome to 153.0.8010.36 or later and restart the browser; verify the running version at chrome://version and ensure auto-updates are enabled across managed fleets. As an interim measure, restrict exposure to untrusted web content, and if you run Chromium-based derivatives, watch for equivalent updates from those vendors incorporating the same Chromium fix.

Affected
google chromeAll versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome holds roughly two-thirds of global browser market share across desktop and mobile) — Chrome's dominant global browser market share implies on the order of billions of installations are potentially affected, though the flaw's Low vendor severity, user-interaction requirement, and DevTools-specific trigger narrow practical…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.