ZeroHour

CVE-2026-87500

mass

Sandbox escape via array index validation flaw in Google Chrome ANGLE

CVSS 3.1
9.6 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-87500 is an improper validation of an array index (CWE-129) in ANGLE, the graphics translation layer in Google Chrome that converts WebGL/OpenGL ES calls to the host GPU API, fixed in Chrome 153.0.8010.36. A remote attacker can trigger the flaw by convincing a user to open a crafted HTML page, with no privileges required and user interaction needed (per the CVSS vector AV:N/AC:L/PR:N/UI:R). Because the bug resides in the ANGLE/GPU component, successful exploitation could let the attacker execute arbitrary code outside Chrome's sandbox, granting broader access to the host than a typical renderer bug — consistent with the changed scope (S:C) in the CVSS vector and Chromium's High severity rating. All users of Google Chrome prior to 153.0.8010.36 are affected. There is currently no evidence of in-the-wild exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.

What to do: Update Google Chrome to 153.0.8010.36 or later via the built-in auto-updater and verify the running build under Settings > About Chrome, relaunching the browser to ensure the patched version is loaded. Organizations managing Chrome via enterprise policies should confirm the updated build has rolled out to all managed endpoints; until patched, limiting exposure to untrusted web content reduces risk given the WebGL/graphics-adjacent nature of the flaw.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome holds roughly 60-65% global browser market share; all unpatched installs prior to 153.0.8010.36 remain vulnerable) — Chrome is the world's most widely used browser with an estimated user base in the billions and roughly 60-65% market share, so potentially every unpatched install is affected, though automatic updates rapidly shrink the vulnerable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-129
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.