ZeroHour

CVE-2026-87578

mass

Use-After-Free in Google Chrome Receiver Enables Out-of-Sandbox Code Execution

CVSS 3.1
8.3 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-87578 is a use-after-free (CWE-416) in the Receiver component of Google Chrome, fixed in version 153.0.8010.36. An attacker in an adjacent network position (per the CVSS AV:A vector) can trigger the flaw by sending crafted network traffic to a vulnerable browser. Successful exploitation allows arbitrary code execution outside the Chrome sandbox, meaning the attacker escapes the browser's strongest isolation layer on the victim machine. All Chrome users running versions prior to 153.0.8010.36 are affected. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as it is available via auto-update or by checking chrome://settings/help. Prioritize patching endpoints on shared or untrusted networks (public Wi-Fi, corporate LANs, VPN-adjacent hosts) since the adjacent-attacker vector requires network proximity. Confirm deployed browser versions across your fleet and block or restrict versions below 153.0.8010.36 until updated.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion Chrome users worldwide (Chrome holds roughly 65% global browser market share; all users on builds before 153.0.8010.36 are affected) — Chrome's install base is in the billions based on public browser market-share data, though the adjacent-network (AV:A) attack requirement means practically exploitable conditions are limited to hosts where an attacker can reach the browser…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.