CVE-2026-87529
massNumeric Truncation Flaw in Google Chrome Media Stack Enables Sandbox-Escape RCE
CVE-2026-87529 is a numeric truncation error (CWE-197) in the Media component of Google Chrome that affects versions prior to 153.0.8010.36. A remote attacker triggers the flaw by luring a user (UI:R) into opening a crafted HTML page, and the truncation error in media processing corrupts data in a way that yields code execution. If exploited, the attacker can potentially execute arbitrary code outside the Chrome sandbox, meaning compromise beyond the renderer's protections, consistent with the CVSS scope-change (S:C) with high confidentiality, integrity and availability impact. Users of Chrome on versions before 153.0.8010.36 are affected, with attack surface limited to the in-browser media/HTML rendering path rather than server-side systems. There is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days; note the severity framing differs between the 9.6 (critical) CVSS score and the Medium Chromium security severity.
What to do: Update Google Chrome to version 153.0.8010.36 or later, forcing the update via the About Chrome (chrome://settings/help) page and confirming the new version number is shown. Enterprise administrators should enforce this build across managed browsers rather than waiting for staggered auto-updates. No workarounds are documented in the disclosure, so patching is the primary mitigation.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-197
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.