CVE-2026-87474
massUse-After-Free in Google Chrome Payments Enables Sandbox-Escape Code Execution
CVE-2026-87474 is a use-after-free memory corruption flaw (CWE-416) in the Payments component of Google Chrome, fixed in Chrome 153.0.8010.36. A remote attacker can trigger it by convincing a user to open a crafted HTML page, which means ordinary browsing activity is sufficient to reach the vulnerable code. Successful exploitation allows the attacker to potentially execute arbitrary code outside the browser sandbox, giving them code execution in the context of the browser process on the victim's machine rather than being confined to a sandboxed renderer. All users running Google Chrome versions prior to 153.0.8010.36 are affected. There is currently no known exploitation in the wild, no public proof of concept, and a low predicted exploitation probability (EPSS 0.4% over 30 days); the flaw is rated High severity by Chromium and carries a CVSS 3.1 score of 9.6.
What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints and verify the running version at chrome://version. Enterprise administrators should enforce the update via Chrome version-pinning/update policies or Chrome Browser Cloud Management and prioritize patching internet-facing workstations where users browse untrusted sites. No workarounds are documented, so patching is the primary mitigation; no exploit or in-the-wild activity is known at this time.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.