ZeroHour

CVE-2026-87455

mass

Use-after-free in Google Chrome Aura enables sandbox-escaping code execution

CVSS 3.1
9.6 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-87455 is a use-after-free memory-safety flaw (CWE-416) in Aura, the UI layer of Google Chrome, affecting all versions prior to 153.0.8010.36. An attacker triggers it by convincing a user (the CVSS vector requires user interaction) to open a crafted HTML page, corrupting freed memory and potentially executing arbitrary code outside the browser sandbox. Successful exploitation would grant code execution with privileges beyond Chrome's sandbox, which drives the 9.6 CVSS scope-change rating, although Google's own Chromium severity rating is only Medium. All Google Chrome users running builds older than 153.0.8010.36 are affected; no other vendor or product is listed in the data. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns just a 0.3% probability of exploitation within 30 days, so no active exploitation is currently known.

What to do: Update Google Chrome to 153.0.8010.36 or later — verify the running version via chrome://settings/help, since Chrome's auto-updater may need a browser restart to apply the fix. Because exploitation requires a user to visit a crafted page, there is no interim mitigation beyond standard browser hygiene, but browser-version patching should be enforced across managed fleets via endpoint or MDM tooling. With no public PoC, no KEV listing, and low EPSS, this can be patched on a normal update cycle rather than as an emergency.

Affected
Google ChromeAll versions prior to 153.0.8010.36 (fixed in 153.0.8010.36)
Estimated exposure
mass≈3+ billion Chrome users (every build prior to 153.0.8010.36 is affected) — Chrome is the world's most widely deployed browser with on the order of 3-4 billion active users and roughly two-thirds of desktop browser share, and the flaw resides in the core Aura component present in all pre-fix builds, so the exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.