CVE-2026-87460
massUse-after-free in Google Chrome Platform component enables sandboxed code execution
CVE-2026-87460 is a use-after-free memory-safety bug (CWE-416) in the Platform component of Google Chrome, rated High severity by the Chromium security team with a CVSS 3.1 score of 8.8. It is triggered when a user loads a crafted HTML page, which causes the browser to access freed memory in a way the attacker can control. Successful exploitation allows a remote attacker to execute arbitrary code inside the Chrome sandbox, meaning the attacker gains code execution in the browser process but must still break out of the sandbox to affect the operating system. All Chrome users running a version prior to 153.0.8010.36 are affected. As of now the flaw is not listed in CISA's KEV catalog, EPSS estimates only a 0.2% probability of exploitation in the next 30 days, and no public proof-of-concept or confirmed in-the-wild exploitation is known.
What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as it is available in your channel; users can verify their version at chrome://settings/help (or chrome://version). Enterprise administrators should confirm that Chrome auto-update policies are functioning and deployed fleet-wide, and until patching is complete, treat browsing to untrusted websites as the primary risk vector. No workaround is documented in the provided data, so patching is the recommended remediation.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.