CVE-2026-87514
massUse-After-Free in Google Chrome Views Component Enables Sandbox Escape
CVE-2026-87514 is a use-after-free memory corruption flaw (CWE-416) in the Views component of Google Chrome, rated High by the Chromium security team. It is triggered by a local program already running on the machine: an attacker who can execute code locally, or who has planted a malicious local program, can trigger the flaw to break out of Chrome's sandbox. Successful exploitation yields arbitrary code execution outside the sandbox, with high impact on confidentiality, integrity, and availability at the system level (CVSS 8.1, AV:L/AC:H/S:C). Anyone running Google Chrome prior to 153.0.8010.36 is affected; exploitation requires a local foothold, so remote-only attackers cannot leverage it directly. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts the 30-day exploitation probability at a low 0.2%.
What to do: Update Google Chrome to 153.0.8010.36 or later (check via chrome://settings/help) on all endpoints, prioritizing shared, multi-user, and kiosk-style systems where local malicious programs are more plausible. No workarounds are documented; because exploitation requires a local attacker, treat this as a defense-in-depth patch rather than an emergency, but do not defer it on hosts where users routinely run untrusted local software.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.