ZeroHour

CVE-2026-87554

mass

TOCTOU race condition sandbox escape in Google Chrome Chromoting on Windows

CVSS 3.1
8.1 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-87554 is a time-of-check/time-of-use (TOCTOU) race condition (CWE-367) in the Chromoting (Chrome Remote Desktop) component of Google Chrome on Windows. It is triggered by a local program that wins a race against Chromoting's checks during the attack window, which the Chromium project rates High severity. A successful exploit lets the local attacker execute arbitrary code outside the Chrome sandbox on the Windows host, but it requires the attacker to already be able to run a program locally; no remote or web-browsing trigger is indicated. Only Google Chrome on Windows prior to 153.0.8010.36 is affected. There is no known in-the-wild exploitation, no public proof-of-concept, it is not in CISA KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.

What to do: Update Google Chrome on Windows to 153.0.8010.36 or later and verify endpoints are current via chrome://settings/help or endpoint management tooling. Because exploitation requires an attacker who can already run a local program, this can follow a normal patch cadence, but prioritize shared, multi-user, or VDI/remote-desktop Windows hosts where local code execution by untrusted users is more likely. Non-Windows Chrome builds are not implicated by this advisory.

Affected
Google ChromeWindows builds prior to 153.0.8010.36
Estimated exposure
mass≈3 billion+ Chrome-on-Windows installs (Chrome's global user base, majority Windows desktop share) — Chrome is the world's most-used browser with roughly 3 billion users, and Windows is the largest desktop platform, so the patched range plausibly covers on the order of billions of installs; practical exploitability is narrower because it…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.