ZeroHour

CVE-2026-87526

mass

Use-after-free in Google Chrome Passwords enables sandbox-escaping code execution

CVSS 3.1
9.6 critical
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-87526 is a use-after-free vulnerability (CWE-416) in the Passwords component of Google Chrome. A remote attacker can trigger it by using social engineering to lure a user into specific UI interactions with the browser's password features. Successful exploitation allows the attacker to execute arbitrary code outside the Chrome sandbox, which means a compromise of the browser process rather than just a renderer-level escape. All users running Chrome prior to version 153.0.8010.36 are affected. There is currently no known in-the-wild exploitation, no public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Chrome to version 153.0.8010.36 or later on all endpoints; verify versions via chrome://settings/help or your endpoint management tooling. Because exploitation requires social engineering plus user interaction with the Passwords UI, reinforce user awareness around unsolicited prompts while patching rolls out. No public exploit or in-the-wild abuse is known, so standard patch cadence is reasonable, but prioritize exposed or high-risk user populations.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global installed base) — Chrome is the world's most widely used browser with a documented installed base in the billions of users, so effectively every Chrome deployment below 153.0.8010.36 is potentially affected, though exploitation requires user interaction and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.