CVE-2026-87480
massUse-after-free in Google Chrome Printing enables code execution outside sandbox
CVE-2026-87480 is a use-after-free (CWE-416) in the Printing component of Google Chrome, fixed in version 153.0.8010.36 and rated High (CVSS 8.3, Chromium severity High). To trigger it, a user must load a crafted HTML page, and the attacker must already have compromised the Chrome renderer process (e.g., by chaining a separate renderer bug), after which the printing bug corrupts freed memory. Successful exploitation potentially allows arbitrary code execution outside the Chrome sandbox, meaning code running with the browser's host privileges rather than confined to the sandbox. Anyone running a Chrome release prior to 153.0.8010.36 is affected, though the high attack complexity and required user interaction temper practical risk. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists; EPSS estimates only a 0.3% chance of exploitation within 30 days.
What to do: Update Chrome to 153.0.8010.36 or later and restart the browser to apply the fix; verify the running version via chrome://settings/help (or chrome://version). Enterprises should force the update through Chrome update management or MDM rather than relying on individual users. Because the bug only yields out-of-sandbox execution after a renderer compromise, keeping Chrome fully patched against other renderer bugs is important defense in depth.
| Google Chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.