AI analysis
CVE-2026-87564 is a type-confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome. A remote attacker can trigger it by luring a user to a crafted HTML page, and successful exploitation lets the attacker read memory from the renderer process inside Chrome's sandbox — an information-disclosure impact (CVSS 4.3, low confidentiality, no integrity or availability loss) that Chromium rates as High severity. Everyone running Google Chrome versions prior to 153.0.8010.36 is affected, spanning the browser's multi-billion-user installed base. The bug is not in CISA's KEV catalog, has no public proof of concept, and carries a low EPSS score (0.2%, percentile 13), but news coverage of the Chrome 153 release (which ships 230 security fixes) reports a zero-day exploited in the wild, so active exploitation of this bug or a companion flaw in the same patch batch is indicated. The fixed version is 153.0.8010.36.
What to do: Update Chrome to 153.0.8010.36 or later immediately on all endpoints (check chrome://settings/help); this stable-channel release fixes this bug among 230 security patches. Confirm auto-update coverage across your fleet and remind users to avoid untrusted links, since exploitation requires visiting a crafted page. If you manage Chromium-based derivatives, verify the vendor has rebuilt with this V8 fix before treating endpoints as patched.
Affected
| google chrome | prior to 153.0.8010.36 |
Estimated exposure
mass≈1–3 billion users on pre-153.0.8010.36 builds (Chrome's global installed base) — Chrome holds roughly two-thirds of global desktop browser share and several billion total users, so the vulnerable population at disclosure is on the order of billions, shrinking rapidly as auto-update rolls out.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.