CVE-2026-87467
massRace Condition in Google Chrome Windows Updater Allows Sandbox-Escape Code Execution
CVE-2026-87467 is a race condition (CWE-362) in the Google Updater component of Chrome for Windows, allowing a local attacker to potentially execute arbitrary code outside the browser sandbox. It is triggered when a local program, already running on the victim machine (e.g., malware or a low-privileged foothold), wins a timing race with updater operations and manipulates the update process. Successful exploitation yields code execution outside Chrome's sandbox, meaning the attacker escapes the browser's isolation boundary and runs with the privileges of the updater/user context. All Chrome installations on Windows prior to 153.0.8010.36 are affected; other platforms are not named in the advisory. There is currently no known public proof-of-concept, no entry in CISA's KEV catalog, and EPSS assigns only a 0.1% (1st percentile) probability of exploitation in the next 30 days, so exploitation status is 'none known'.
What to do: Update Chrome on Windows to 153.0.8010.36 or later and verify the current version at chrome://settings/help; enterprise admins should enforce the minimum browser version via update management policies. Because the flaw requires an attacker to already run a program locally, prioritize patching on shared, multi-user, or remotely accessible endpoints and confirm the Google Updater component picked up the patched build after the browser update.
| Google Chrome | All versions on Windows prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.