ZeroHour

CVE-2026-87533

PoC mass

Use-after-free in Google Chrome DevTools enables local sandbox escape (CVE-2026-87533)

CVSS 3.1
8.1 high
EPSS
<1%p1
Published
()
Modified
AI analysis

Google Chrome versions prior to 153.0.8010.36 contain a use-after-free vulnerability in the DevTools component (CWE-416). The flaw is triggered by a local program running on the same machine, which can exploit the memory-corruption condition during browser operation. Successful exploitation allows the local attacker to execute arbitrary code outside the Chrome sandbox, with a changed security scope and high confidentiality, integrity, and availability impact on the host. All Chrome users running an affected build are exposed in principle, but the attack requires local access and high attack complexity, so remote or web-based attackers cannot leverage it directly. No public proof of concept is known, the issue is not in CISA's KEV catalog, and EPSS currently estimates only a 0.1% probability of exploitation within 30 days.

What to do: Update Chrome to 153.0.8010.36 or later as soon as practical and verify the installed version via chrome://settings/help with automatic updates enabled. Prioritize patching shared, multi-user, and kiosk-style endpoints and any hosts where untrusted local programs run, since exploitation requires a local attacker. Given no known exploitation or public PoC, standard patch cadence is acceptable, but confirm remediation across your managed browser fleet.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome's global installed base; all builds before 153.0.8010.36) — Chrome is the world's dominant desktop browser with a multi-billion-user installed base and the flaw affects all builds prior to the fixed release, though exploitation requires a local attacker, limiting practical exposure to hosts running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.