CVE-2026-87542
massUse-After-Free in Google Chrome Input Component (Sandboxed RCE)
CVE-2026-87542 is a use-after-free flaw (CWE-416) in the Input component of Google Chrome, rated High (CVSS 8.8). A remote attacker can trigger it by persuading a user to visit a crafted HTML page, which the CVSS vector reflects as required user interaction (UI:R). Successful exploitation allows arbitrary code execution inside the Chrome sandbox, with high impact on confidentiality, integrity, and availability, though the advisory does not indicate a sandbox escape. All users running Google Chrome versions prior to 153.0.8010.36 are affected. Exploitation status is quiet: no public proof-of-concept, no CISA KEV listing, and a low EPSS probability of 0.2% over the next 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the update completed on each endpoint via chrome://settings/help. Inventory managed fleets with EDR or browser-management tooling for Chrome builds below this version and prioritize patching high-risk users. No workarounds are documented; treat links to untrusted or crafted web pages as the primary infection vector until patched.
| Google Chrome | prior to 153.0.8010.36 (< 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.