ZeroHour

CVE-2026-87467

mass

Race Condition in Google Chrome Windows Updater Allows Sandbox-Escape Code Execution

CVSS 3.1
8.1 high
EPSS
<1%p0
Published
()
Modified
AI analysis

CVE-2026-87467 is a race condition (CWE-362) in the Google Updater component of Chrome for Windows, allowing a local attacker to potentially execute arbitrary code outside the browser sandbox. It is triggered when a local program, already running on the victim machine (e.g., malware or a low-privileged foothold), wins a timing race with updater operations and manipulates the update process. Successful exploitation yields code execution outside Chrome's sandbox, meaning the attacker escapes the browser's isolation boundary and runs with the privileges of the updater/user context. All Chrome installations on Windows prior to 153.0.8010.36 are affected; other platforms are not named in the advisory. There is currently no known public proof-of-concept, no entry in CISA's KEV catalog, and EPSS assigns only a 0.1% (1st percentile) probability of exploitation in the next 30 days, so exploitation status is 'none known'.

What to do: Update Chrome on Windows to 153.0.8010.36 or later and verify the current version at chrome://settings/help; enterprise admins should enforce the minimum browser version via update management policies. Because the flaw requires an attacker to already run a program locally, prioritize patching on shared, multi-user, or remotely accessible endpoints and confirm the Google Updater component picked up the patched build after the browser update.

Affected
Google ChromeAll versions on Windows prior to 153.0.8010.36
Estimated exposure
mass≈3 billion users (Chrome's global installed base, with Windows builds comprising the majority of desktop installs) — Chrome is the world's most widely used browser with roughly three billion users and Windows dominates the desktop OS market, so the affected local-attack surface spans essentially all Windows Chrome endpoints, though exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Race condition in Updater in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.