ZeroHour

CVE-2026-87529

mass

Numeric Truncation Flaw in Google Chrome Media Stack Enables Sandbox-Escape RCE

CVSS 3.1
9.6 critical
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-87529 is a numeric truncation error (CWE-197) in the Media component of Google Chrome that affects versions prior to 153.0.8010.36. A remote attacker triggers the flaw by luring a user (UI:R) into opening a crafted HTML page, and the truncation error in media processing corrupts data in a way that yields code execution. If exploited, the attacker can potentially execute arbitrary code outside the Chrome sandbox, meaning compromise beyond the renderer's protections, consistent with the CVSS scope-change (S:C) with high confidentiality, integrity and availability impact. Users of Chrome on versions before 153.0.8010.36 are affected, with attack surface limited to the in-browser media/HTML rendering path rather than server-side systems. There is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days; note the severity framing differs between the 9.6 (critical) CVSS score and the Medium Chromium security severity.

What to do: Update Google Chrome to version 153.0.8010.36 or later, forcing the update via the About Chrome (chrome://settings/help) page and confirming the new version number is shown. Enterprise administrators should enforce this build across managed browsers rather than waiting for staggered auto-updates. No workarounds are documented in the disclosure, so patching is the primary mitigation.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
masshundreds of millions of users (Chrome's global install base is in the billions; vulnerable users are those not yet updated to 153.0.8010.36) — Chrome's worldwide user base is on the order of billions, and because auto-update rollout is staggered, a substantial fraction of users can remain on pre-153.0.8010.36 builds for days to weeks, plausibly amounting to hundreds of millions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-197
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.