ZeroHour

CVE-2026-87558

mass

Use-After-Free in Google Chrome Payments on macOS Enables Sandbox-Escape RCE

CVSS 3.1
9.6 critical
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-87558 is a use-after-free (CWE-416) in the Payments component of Google Chrome on Mac, rated High by Chromium and 9.6 (Critical) under CVSS 3.1. A remote attacker can trigger it by convincing a user to open a crafted HTML page, the user interaction reflected in the CVSS vector (UI:R). Successful exploitation allows the attacker to execute arbitrary code outside Chrome's sandbox, meaning code runs with browser-level privileges on the Mac rather than being confined to the renderer. Affected users are those running Chrome on macOS in versions prior to 153.0.8010.36; the advisory does not list other platforms. There is currently no public proof-of-concept, no entry in CISA KEV, and a low EPSS score (0.3%, 22nd percentile), indicating no known exploitation at this time.

What to do: Update Chrome on macOS to version 153.0.8010.36 or later via chrome://settings/help or your managed update channel, and verify deployed browser versions across macOS fleets using enterprise management tooling. Until patched, limit exposure by having users on Mac avoid opening HTML content from untrusted sources. Given the flaw allows code execution outside the sandbox, treat patching as high priority even though no in-the-wild exploitation is known.

Affected
google chromeChrome on Mac prior to 153.0.8010.36 (macOS only; all earlier versions of the affected branch)
Estimated exposure
masshundreds of millions of Chrome users on macOS — Chrome's multi-billion desktop user base multiplied by macOS's roughly 15-20% desktop operating-system share implies hundreds of millions of Chrome-on-Mac users, though the Payments-component scope narrows the vulnerable code path to that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.