ZeroHour

CVE-2026-87457

mass

Race Condition in Google Chrome Updater on Windows Allows Local Code Execution

CVSS 3.1
8.1 high
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-87457 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in the Google Chrome Updater component on Windows. A local attacker who can already run a program on an affected Windows machine can exploit the race window in the updater to execute arbitrary code outside of Chrome's sandbox. Successful exploitation yields code execution with privileges beyond the browser sandbox, but it requires local access rather than any remote or network path; the CVSS v3.1 base score is 8.1 (High, local/complex attack with changed scope), while Chromium rates the severity Medium. The flaw affects Google Chrome on Windows prior to version 153.0.8010.36; other platforms are not named in the advisory. There is no evidence of exploitation so far: no public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates only a 0.1% probability of exploitation within 30 days.

What to do: Update Google Chrome on Windows to 153.0.8010.36 or later; open Settings > About Chrome to force the (affected) updater to fetch the fix, then confirm the running version at chrome://version. Enterprises should verify fleet-wide versions through their update-management tooling and prioritize endpoints exposed to untrusted local users or commodity malware. Non-Windows Chrome installations are not implicated by this advisory.

Affected
Google Chrome (on Windows)All versions prior to 153.0.8010.36
Estimated exposure
mass~1 billion+ Chrome-on-Windows installations — Chrome holds roughly two-thirds of desktop browser usage share and Windows is the majority desktop OS, implying on the order of a billion or more Chrome-on-Windows installs per public market-share data, though the flaw is only exploitable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.