ZeroHour

CVE-2026-87497

PoC mass

Uninitialized memory read in Google Chrome codecs prior to 153.0.8010.36

CVSS 3.1
4.3 medium
EPSS
<1%p11
Published
()
Modified
AI analysis

CVE-2026-87497 is an uninitialized resource flaw (CWE-908) in the codecs component of Google Chrome, where memory is used without being initialized first. A remote attacker can trigger it by luring a user to visit a specially crafted HTML page, with user interaction required. Successful exploitation lets the attacker read memory inside the browser sandbox — a limited, read-only information disclosure with no confidentiality beyond in-sandbox contents, and no indication of sandbox escape or code execution. Users of Google Chrome prior to version 153.0.8010.36 are affected. There are no reports of in-the-wild exploitation and the flaw is not in CISA KEV; one public proof-of-concept reference exists in the Chromium issue tracker and EPSS currently estimates a 0.2% chance of exploitation within 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later (verify via chrome://settings/help or the equivalent enterprise update policy) and ensure browser auto-updates are enforced across the fleet. No workaround is needed beyond patching, as no in-the-wild exploitation is known, but prioritize the update on internet-facing and high-risk endpoints where users browse untrusted sites.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
masshundreds of millions to billions of Chrome installations — Chrome is the dominant desktop and mobile browser with roughly 65% market share and an estimated multi-billion active install base, and every install below version 153.0.8010.36 is affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-908
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.