ZeroHour

CVE-2026-87460

mass

Use-after-free in Google Chrome Platform component enables sandboxed code execution

CVSS 3.1
8.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-87460 is a use-after-free memory-safety bug (CWE-416) in the Platform component of Google Chrome, rated High severity by the Chromium security team with a CVSS 3.1 score of 8.8. It is triggered when a user loads a crafted HTML page, which causes the browser to access freed memory in a way the attacker can control. Successful exploitation allows a remote attacker to execute arbitrary code inside the Chrome sandbox, meaning the attacker gains code execution in the browser process but must still break out of the sandbox to affect the operating system. All Chrome users running a version prior to 153.0.8010.36 are affected. As of now the flaw is not listed in CISA's KEV catalog, EPSS estimates only a 0.2% probability of exploitation in the next 30 days, and no public proof-of-concept or confirmed in-the-wild exploitation is known.

What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as it is available in your channel; users can verify their version at chrome://settings/help (or chrome://version). Enterprise administrators should confirm that Chrome auto-update policies are functioning and deployed fleet-wide, and until patching is complete, treat browsing to untrusted websites as the primary risk vector. No workaround is documented in the provided data, so patching is the recommended remediation.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
masshundreds of millions to billions of users (Chrome is the world's most widely used browser) — Chrome has a multi-billion-user install base and dominant desktop browser market share, so effectively every unpatched installation prior to 153.0.8010.36 is exposed to malicious web pages; the exact count of not-yet-updated installs is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Platform in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.