ZeroHour

CVE-2026-87524

mass

Use-after-free in Google Chrome for Windows enables sandbox escape (CVE-2026-87524)

CVSS 3.1
8.3 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-87524 is a use-after-free (CWE-416) in the Core component of Google Chrome on Windows, fixed in 153.0.8010.36. To trigger it, a remote attacker first compromises the Chrome renderer process and then lures the user to a crafted HTML page, where the memory-reuse flaw can be exploited. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox, meaning code can run with access beyond the browser's renderer isolation, with high confidentiality, integrity and availability impact. Anyone running Chrome on Windows prior to 153.0.8010.36 is affected; other platforms are not named in the advisory. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Update Chrome on Windows to 153.0.8010.36 or later, or confirm auto-update has applied the patch by checking chrome://version; enterprise administrators should verify fleet versions via update management tooling. Because exploitation requires first compromising the renderer, prioritizing this update alongside patching any other active Chrome vulnerabilities provides defense in depth.

Affected
Google ChromeChrome on Windows, all versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions of Windows Chrome installations (Chrome holds roughly 65% desktop browser share with billions of total users) — Chrome is the dominant desktop browser with an install base in the billions, so the Windows subset on unpatched pre-153.0.8010.36 builds plausibly reaches the hundreds of millions, though the flaw requires the attacker to chain from an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Core in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.