CVE-2026-87455
massUse-after-free in Google Chrome Aura enables sandbox-escaping code execution
CVE-2026-87455 is a use-after-free memory-safety flaw (CWE-416) in Aura, the UI layer of Google Chrome, affecting all versions prior to 153.0.8010.36. An attacker triggers it by convincing a user (the CVSS vector requires user interaction) to open a crafted HTML page, corrupting freed memory and potentially executing arbitrary code outside the browser sandbox. Successful exploitation would grant code execution with privileges beyond Chrome's sandbox, which drives the 9.6 CVSS scope-change rating, although Google's own Chromium severity rating is only Medium. All Google Chrome users running builds older than 153.0.8010.36 are affected; no other vendor or product is listed in the data. There is no known public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS assigns just a 0.3% probability of exploitation within 30 days, so no active exploitation is currently known.
What to do: Update Google Chrome to 153.0.8010.36 or later — verify the running version via chrome://settings/help, since Chrome's auto-updater may need a browser restart to apply the fix. Because exploitation requires a user to visit a crafted page, there is no interim mitigation beyond standard browser hygiene, but browser-version patching should be enforced across managed fleets via endpoint or MDM tooling. With no public PoC, no KEV listing, and low EPSS, this can be patched on a normal update cycle rather than as an emergency.
| Google Chrome | All versions prior to 153.0.8010.36 (fixed in 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Aura in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.