CVE-2026-87526
massUse-after-free in Google Chrome Passwords enables sandbox-escaping code execution
CVE-2026-87526 is a use-after-free vulnerability (CWE-416) in the Passwords component of Google Chrome. A remote attacker can trigger it by using social engineering to lure a user into specific UI interactions with the browser's password features. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox, which means a compromise of the browser process rather than just a renderer-level escape. All users running Chrome prior to version 153.0.8010.36 are affected. There is currently no known in-the-wild exploitation, no public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update Chrome to version 153.0.8010.36 or later on all endpoints; verify versions via chrome://settings/help or your endpoint management tooling. Because exploitation requires social engineering plus user interaction with the Passwords UI, reinforce user awareness around unsolicited prompts while patching rolls out. No public exploit or in-the-wild abuse is known, so standard patch cadence is reasonable, but prioritize exposed or high-risk user populations.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.