CVE-2026-87494
massUse-after-free in Google Chrome on Windows permits code execution outside sandbox
CVE-2026-87494 is a use-after-free memory-safety flaw (CWE-416) in the browser component of Google Chrome on Windows. A remote attacker exploits it by persuading a user, via social engineering, to open or interact with a crafted HTML page, and successful exploitation yields arbitrary code execution outside Chrome's sandbox. The provided CVSS 3.1 base score is 9.6 (critical), although the Chromium project itself rates the severity as Medium, reflecting the required user interaction. Anyone running an affected Chrome build on Windows prior to 153.0.8010.36 is exposed; per the data, non-Windows platforms are not listed as affected. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at roughly 0.2%, so no known exploitation is underway.
What to do: Update Chrome on Windows to version 153.0.8010.36 or later, verifying the patched version at chrome://settings/help or via your enterprise update channel. Because exploitation depends on social engineering, remind users to be cautious about opening links and HTML pages from untrusted sources. Non-Windows Chrome installs are not listed as affected, but keeping all browsers current is prudent.
| Google Chrome | on Windows, all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Browser in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.