CVE-2026-87533
PoC massUse-after-free in Google Chrome DevTools enables local sandbox escape (CVE-2026-87533)
Google Chrome versions prior to 153.0.8010.36 contain a use-after-free vulnerability in the DevTools component (CWE-416). The flaw is triggered by a local program running on the same machine, which can exploit the memory-corruption condition during browser operation. Successful exploitation allows the local attacker to execute arbitrary code outside the Chrome sandbox, with a changed security scope and high confidentiality, integrity, and availability impact on the host. All Chrome users running an affected build are exposed in principle, but the attack requires local access and high attack complexity, so remote or web-based attackers cannot leverage it directly. No public proof of concept is known, the issue is not in CISA's KEV catalog, and EPSS currently estimates only a 0.1% probability of exploitation within 30 days.
What to do: Update Chrome to 153.0.8010.36 or later as soon as practical and verify the installed version via chrome://settings/help with automatic updates enabled. Prioritize patching shared, multi-user, and kiosk-style endpoints and any hosts where untrusted local programs run, since exploitation requires a local attacker. Given no known exploitation or public PoC, standard patch cadence is acceptable, but confirm remediation across your managed browser fleet.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.