ZeroHour

CVE-2026-87494

mass

Use-after-free in Google Chrome on Windows permits code execution outside sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-87494 is a use-after-free memory-safety flaw (CWE-416) in the browser component of Google Chrome on Windows. A remote attacker exploits it by persuading a user, via social engineering, to open or interact with a crafted HTML page, and successful exploitation yields arbitrary code execution outside Chrome's sandbox. The provided CVSS 3.1 base score is 9.6 (critical), although the Chromium project itself rates the severity as Medium, reflecting the required user interaction. Anyone running an affected Chrome build on Windows prior to 153.0.8010.36 is exposed; per the data, non-Windows platforms are not listed as affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no known exploitation is underway.

What to do: Update Chrome on Windows to version 153.0.8010.36 or later, verifying the patched version at chrome://settings/help or via your enterprise update channel. Because exploitation depends on social engineering, remind users to be cautious about opening links and HTML pages from untrusted sources. Non-Windows Chrome installs are not listed as affected, but keeping all browsers current is prudent.

Affected
Google Chromeon Windows, all versions prior to 153.0.8010.36
Estimated exposure
masson the order of hundreds of millions of users (desktop Chrome on Windows) — Chrome holds roughly two-thirds of desktop browser market share with billions of global users and Windows is the dominant desktop OS, so the number of Windows Chrome installs far exceeds the mass threshold; the exact count of unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.