ZeroHour

CVE-2026-87579

mass

Buffer Overflow in Google Chrome WebRTC Allows Sandboxed Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-87579 is a buffer overflow (CWE-122) in the WebRTC component of Google Chrome that is fixed in version 153.0.8010.36. It is triggered when a victim visits a crafted HTML page, which causes the malformed input to be processed by WebRTC and overflows a buffer. A successful attacker gains the ability to execute arbitrary code inside the Chrome renderer sandbox, which limits the blast radius of the compromise to the web-content sandbox rather than the whole system. All users running Google Chrome versions prior to 153.0.8010.36 are affected. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation risk at about 0.2%; note that the Chrome 153 release headline mentions a separately exploited zero-day, but the data does not tie that zero-day to this CVE.

What to do: Update Google Chrome to version 153.0.8010.36 or later, which is available via the Chrome update mechanism (chrome://settings/help). Until patched, avoid untrusted web pages that make heavy use of WebRTC, and confirm fleet versions via endpoint management or MDM reporting.

Affected
Google ChromeAll versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions to billions of users (Chrome's global install base) — Google Chrome is the world's dominant desktop browser with a user base on the order of billions, and users on any release before 153.0.8010.36 remain exposed until they update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs