CVE-2026-87524
massUse-after-free in Google Chrome for Windows enables sandbox escape (CVE-2026-87524)
CVE-2026-87524 is a use-after-free (CWE-416) in the Core component of Google Chrome on Windows, fixed in 153.0.8010.36. To trigger it, a remote attacker first compromises the Chrome renderer process and then lures the user to a crafted HTML page, where the memory-reuse flaw can be exploited. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox, meaning code can run with access beyond the browser's renderer isolation, with high confidentiality, integrity and availability impact. Anyone running Chrome on Windows prior to 153.0.8010.36 is affected; other platforms are not named in the advisory. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Update Chrome on Windows to 153.0.8010.36 or later, or confirm auto-update has applied the patch by checking chrome://version; enterprise administrators should verify fleet versions via update management tooling. Because exploitation requires first compromising the renderer, prioritizing this update alongside patching any other active Chrome vulnerabilities provides defense in depth.
| Google Chrome | Chrome on Windows, all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.