ZeroHour

CVE-2026-87474

mass

Use-After-Free in Google Chrome Payments Enables Sandbox-Escape Code Execution

CVSS 3.1
9.6 critical
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-87474 is a use-after-free memory corruption flaw (CWE-416) in the Payments component of Google Chrome, fixed in Chrome 153.0.8010.36. A remote attacker can trigger it by convincing a user to open a crafted HTML page, which means ordinary browsing activity is sufficient to reach the vulnerable code. Successful exploitation allows the attacker to potentially execute arbitrary code outside the browser sandbox, giving them code execution in the context of the browser process on the victim's machine rather than being confined to a sandboxed renderer. All users running Google Chrome versions prior to 153.0.8010.36 are affected. There is currently no known exploitation in the wild, no public proof of concept, and a low predicted exploitation probability (EPSS 0.4% over 30 days); the flaw is rated High severity by Chromium and carries a CVSS 3.1 score of 9.6.

What to do: Update Google Chrome to 153.0.8010.36 or later on all endpoints and verify the running version at chrome://version. Enterprise administrators should enforce the update via Chrome version-pinning/update policies or Chrome Browser Cloud Management and prioritize patching internet-facing workstations where users browse untrusted sites. No workarounds are documented, so patching is the primary mitigation; no exploit or in-the-wild activity is known at this time.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
masson the order of billions of Chrome users (Chrome's global install base is roughly 3+ billion) — Chrome is the world's most widely used desktop and mobile browser with billions of active installations per public market-share statistics, and the Payments component ships in all standard Chrome builds; exploitation additionally requires…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.