ZeroHour

CVE-2026-87488

mass1

Use-After-Free in WebGL in Google Chrome for Android Allows RCE Outside Sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p41
Published
()
Modified
AI analysis

CVE-2026-87488 is a use-after-free (CWE-416) in the WebGL component of Google Chrome on Android, fixed in Chrome 153.0.8010.36. A remote attacker triggers it by luring a user to open a crafted HTML page in a vulnerable Chrome for Android build. Successful exploitation allows the attacker to execute arbitrary code outside the browser's sandbox, meaning code runs beyond the browser's security boundary on the device. All Chrome for Android users running versions prior to 153.0.8010.36 are affected. No public proof-of-concept is known and the flaw is not in CISA's KEV, with EPSS assigning a 0.4% 30-day exploitation probability; note that the same Chrome 153 release fixes 230 issues, including a separate, actively exploited V8 zero-day (code execution inside the sandbox) that should not be confused with this WebGL bug.

What to do: Update Chrome for Android to 153.0.8010.36 or later via the Google Play Store, and verify managed fleets through MDM/EMM browser version reporting. Because this flaw allows code execution outside the sandbox, treat it as critical and patch promptly, especially since the same 153 release also addresses an actively exploited V8 zero-day. Until devices are patched, avoid opening untrusted links or web content in Chrome on Android.

Affected
Google Chrome for AndroidAll versions prior to 153.0.8010.36
Estimated exposure
mass~billions of users (Chrome for Android has a global install base in the billions; every Android build before 153.0.8010.36 is affected) — Chrome is the dominant browser on Android, the world's most widely used mobile operating system, giving an affected population on the order of billions of devices until users update to 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in WebGL in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google patches actively exploited Chrome V8 zero-day CVE-2026-87491, an out-of-bounds write enabling sandboxed code execution via crafted HTML pages.

Google released Chrome 153.0.8010.36/.37 fixing 230 vulnerabilities, including CVE-2026-87491, an out-of-bounds write in the V8 engine that allowed remote code execution inside the sandbox via a crafted HTML page and is confirmed to be exploited in the wild. The flaw was reported on August 6, 2026 by Jihyeon Jeong of Compsec Lab, Seoul National University, who received a $2,500 bug bounty. This is the seventh actively exploited Chrome zero-day of 2026. The update also fixes five critical flaws in WebGL and Cast, plus a high WebPackaging use-after-free (CVE-2026-87639) credited to OpenAI Codex Security.

The Hacker News · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-2441CVE-2026-3909+10 CVEs

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs

Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

Google shipped Chrome 153 with 230 fixes, including CVE-2026-87491, a V8 out-of-bounds write zero-day exploited in the wild.

Chrome 153 (153.0.8010.36/.37) rolls out to Windows, Mac, and Linux with 230 security fixes, among the largest patch batches in recent Chrome history. The headline flaw is CVE-2026-87491, a Medium-severity out-of-bounds write in the V8 JavaScript and WebAssembly engine that Google confirmed is exploited in the wild; it was reported by Jihyeon Jeong of Compsec Lab at Seoul National University for a $2,500 bounty. The release also closes five Critical-rated flaws, including CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628, mostly use-after-free and out-of-bounds write bugs in WebGL and Cast, plus 43 High-severity issues across ANGLE, PDFium, V8, DevTools, and Payments. Several bugs were surfaced with AI-assisted discovery tools, including OpenAI's Codex Security team, and top bounties reached $5,000 for CVE-2026-87504.