ZeroHour

CVE-2026-87564

mass

Type Confusion in Google Chrome V8 Allows In-Sandbox Memory Read

CVSS 3.1
4.3 medium
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-87564 is a type-confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome. A remote attacker can trigger it by luring a user to a crafted HTML page, and successful exploitation lets the attacker read memory from the renderer process inside Chrome's sandbox — an information-disclosure impact (CVSS 4.3, low confidentiality, no integrity or availability loss) that Chromium rates as High severity. Everyone running Google Chrome versions prior to 153.0.8010.36 is affected, spanning the browser's multi-billion-user installed base. The bug is not in CISA's KEV catalog, has no public proof of concept, and carries a low EPSS score (0.2%, percentile 13), but news coverage of the Chrome 153 release (which ships 230 security fixes) reports a zero-day exploited in the wild, so active exploitation of this bug or a companion flaw in the same patch batch is indicated. The fixed version is 153.0.8010.36.

What to do: Update Chrome to 153.0.8010.36 or later immediately on all endpoints (check chrome://settings/help); this stable-channel release fixes this bug among 230 security patches. Confirm auto-update coverage across your fleet and remind users to avoid untrusted links, since exploitation requires visiting a crafted page. If you manage Chromium-based derivatives, verify the vendor has rebuilt with this V8 fix before treating endpoints as patched.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
mass≈1–3 billion users on pre-153.0.8010.36 builds (Chrome's global installed base) — Chrome holds roughly two-thirds of global desktop browser share and several billion total users, so the vulnerable population at disclosure is on the order of billions, shrinking rapidly as auto-update rolls out.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs