ZeroHour

CVE-2026-87480

mass

Use-after-free in Google Chrome Printing enables code execution outside sandbox

CVSS 3.1
8.3 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-87480 is a use-after-free (CWE-416) in the Printing component of Google Chrome, fixed in version 153.0.8010.36 and rated High (CVSS 8.3, Chromium severity High). To trigger it, a user must load a crafted HTML page, and the attacker must already have compromised the Chrome renderer process (e.g., by chaining a separate renderer bug), after which the printing bug corrupts freed memory. Successful exploitation potentially allows arbitrary code execution outside the Chrome sandbox, meaning code running with the browser's host privileges rather than confined to the sandbox. Anyone running a Chrome release prior to 153.0.8010.36 is affected, though the high attack complexity and required user interaction temper practical risk. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists; EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Update Chrome to 153.0.8010.36 or later and restart the browser to apply the fix; verify the running version via chrome://settings/help (or chrome://version). Enterprises should force the update through Chrome update management or MDM rather than relying on individual users. Because the bug only yields out-of-sandbox execution after a renderer compromise, keeping Chrome fully patched against other renderer bugs is important defense in depth.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
mass≈3 billion users (Chrome holds roughly 60-65% of global browser share) — Chrome is the world's dominant desktop and mobile browser with a publicly reported global user base above three billion, so effectively every Chrome user on a pre-153.0.8010.36 build is plausibly exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Printing in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.