ZeroHour

CVE-2026-87542

mass

Use-After-Free in Google Chrome Input Component (Sandboxed RCE)

CVSS 3.1
8.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-87542 is a use-after-free flaw (CWE-416) in the Input component of Google Chrome, rated High (CVSS 8.8). A remote attacker can trigger it by persuading a user to visit a crafted HTML page, which the CVSS vector reflects as required user interaction (UI:R). Successful exploitation allows arbitrary code execution inside the Chrome sandbox, with high impact on confidentiality, integrity, and availability, though the advisory does not indicate a sandbox escape. All users running Google Chrome versions prior to 153.0.8010.36 are affected. Exploitation status is quiet: no public proof-of-concept, no CISA KEV listing, and a low EPSS probability of 0.2% over the next 30 days.

What to do: Update Google Chrome to 153.0.8010.36 or later and verify the update completed on each endpoint via chrome://settings/help. Inventory managed fleets with EDR or browser-management tooling for Chrome builds below this version and prioritize patching high-risk users. No workarounds are documented; treat links to untrusted or crafted web pages as the primary infection vector until patched.

Affected
Google Chromeprior to 153.0.8010.36 (< 153.0.8010.36)
Estimated exposure
mass≈2–3 billion users (Chrome holds roughly two-thirds of global browser market share) — Chrome's ~65% share of a multi-billion-user global browser base means the population running pre-153.0.8010.36 builds at disclosure is plausibly in the billions, shrinking rapidly as Chrome's auto-update propagates the fix.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.