CVE-2026-87581
massUse-After-Free in Google Chrome Payments Enables Sandbox-Escape Code Execution
CVE-2026-87581 is a use-after-free memory corruption flaw in the Payments component of Google Chrome, fixed in version 153.0.8010.36. An attacker triggers it by luring a user to a crafted HTML page, relying on social engineering and user interaction to reach the vulnerable code path. Successful exploitation could allow arbitrary code execution outside the browser sandbox, giving the attacker code running with broader privileges than typical in-sandbox Chrome exploits. Anyone running Google Chrome prior to 153.0.8010.36 is affected. As of now there is no known exploitation in the wild, no public proof-of-concept, and EPSS puts 30-day exploitation probability at only 0.3%, though the High Chromium severity and critical CVSS (9.6) warrant prompt patching.
What to do: Update Chrome to 153.0.8010.36 or later on all endpoints, and verify fleet-wide browser versions via your device management or patch-reporting tools. Until patched, treat social-engineering vectors as the main risk: caution users against interacting with untrusted pages, since the flaw requires user interaction but can yield sandbox-escaping code execution. Given the low EPSS and absence of a public PoC, there is no evidence of active targeting, but apply the update on normal high-priority patch cycles.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.