CVE-2026-87497
PoC massUninitialized memory read in Google Chrome codecs prior to 153.0.8010.36
CVE-2026-87497 is an uninitialized resource flaw (CWE-908) in the codecs component of Google Chrome, where memory is used without being initialized first. A remote attacker can trigger it by luring a user to visit a specially crafted HTML page, with user interaction required. Successful exploitation lets the attacker read memory inside the browser sandbox — a limited, read-only information disclosure with no confidentiality beyond in-sandbox contents, and no indication of sandbox escape or code execution. Users of Google Chrome prior to version 153.0.8010.36 are affected. There are no reports of in-the-wild exploitation and the flaw is not in CISA KEV; one public proof-of-concept reference exists in the Chromium issue tracker and EPSS currently estimates a 0.2% chance of exploitation within 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later (verify via chrome://settings/help or the equivalent enterprise update policy) and ensure browser auto-updates are enforced across the fleet. No workaround is needed beyond patching, as no in-the-wild exploitation is known, but prioritize the update on internet-facing and high-risk endpoints where users browse untrusted sites.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-908
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.