CVE-2026-87554
massTOCTOU race condition sandbox escape in Google Chrome Chromoting on Windows
CVE-2026-87554 is a time-of-check/time-of-use (TOCTOU) race condition (CWE-367) in the Chromoting (Chrome Remote Desktop) component of Google Chrome on Windows. It is triggered by a local program that wins a race against Chromoting's checks during the attack window, which the Chromium project rates High severity. A successful exploit lets the local attacker execute arbitrary code outside the Chrome sandbox on the Windows host, but it requires the attacker to already be able to run a program locally; no remote or web-browsing trigger is indicated. Only Google Chrome on Windows prior to 153.0.8010.36 is affected. There is no known in-the-wild exploitation, no public proof-of-concept, it is not in CISA KEV, and EPSS estimates only about a 0.1% chance of exploitation in the next 30 days.
What to do: Update Google Chrome on Windows to 153.0.8010.36 or later and verify endpoints are current via chrome://settings/help or endpoint management tooling. Because exploitation requires an attacker who can already run a local program, this can follow a normal patch cadence, but prioritize shared, multi-user, or VDI/remote-desktop Windows hosts where local code execution by untrusted users is more likely. Non-Windows Chrome builds are not implicated by this advisory.
| Google Chrome | Windows builds prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Race condition in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.