CVE-2026-87578
massUse-After-Free in Google Chrome Receiver Enables Out-of-Sandbox Code Execution
CVE-2026-87578 is a use-after-free (CWE-416) in the Receiver component of Google Chrome, fixed in version 153.0.8010.36. An attacker in an adjacent network position (per the CVSS AV:A vector) can trigger the flaw by sending crafted network traffic to a vulnerable browser. Successful exploitation allows arbitrary code execution outside the Chrome sandbox, meaning the attacker escapes the browser's strongest isolation layer on the victim machine. All Chrome users running versions prior to 153.0.8010.36 are affected. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% probability of exploitation within 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later as soon as it is available via auto-update or by checking chrome://settings/help. Prioritize patching endpoints on shared or untrusted networks (public Wi-Fi, corporate LANs, VPN-adjacent hosts) since the adjacent-attacker vector requires network proximity. Confirm deployed browser versions across your fleet and block or restrict versions below 153.0.8010.36 until updated.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Receiver in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.