CVE-2026-87558
massUse-After-Free in Google Chrome Payments on macOS Enables Sandbox-Escape RCE
CVE-2026-87558 is a use-after-free (CWE-416) in the Payments component of Google Chrome on Mac, rated High by Chromium and 9.6 (Critical) under CVSS 3.1. A remote attacker can trigger it by convincing a user to open a crafted HTML page, the user interaction reflected in the CVSS vector (UI:R). Successful exploitation allows the attacker to execute arbitrary code outside Chrome's sandbox, meaning code runs with browser-level privileges on the Mac rather than being confined to the renderer. Affected users are those running Chrome on macOS in versions prior to 153.0.8010.36; the advisory does not list other platforms. There is currently no public proof-of-concept, no entry in CISA KEV, and a low EPSS score (0.3%, 22nd percentile), indicating no known exploitation at this time.
What to do: Update Chrome on macOS to version 153.0.8010.36 or later via chrome://settings/help or your managed update channel, and verify deployed browser versions across macOS fleets using enterprise management tooling. Until patched, limit exposure by having users on Mac avoid opening HTML content from untrusted sources. Given the flaw allows code execution outside the sandbox, treat patching as high priority even though no in-the-wild exploitation is known.
| google chrome | Chrome on Mac prior to 153.0.8010.36 (macOS only; all earlier versions of the affected branch) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Payments in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.