ZeroHour

CVE-2026-87581

mass

Use-After-Free in Google Chrome Payments Enables Sandbox-Escape Code Execution

CVSS 3.1
9.6 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-87581 is a use-after-free memory corruption flaw in the Payments component of Google Chrome, fixed in version 153.0.8010.36. An attacker triggers it by luring a user to a crafted HTML page, relying on social engineering and user interaction to reach the vulnerable code path. Successful exploitation could allow arbitrary code execution outside the browser sandbox, giving the attacker code running with broader privileges than typical in-sandbox Chrome exploits. Anyone running Google Chrome prior to 153.0.8010.36 is affected. As of now there is no known exploitation in the wild, no public proof-of-concept, and EPSS puts 30-day exploitation probability at only 0.3%, though the High Chromium severity and critical CVSS (9.6) warrant prompt patching.

What to do: Update Chrome to 153.0.8010.36 or later on all endpoints, and verify fleet-wide browser versions via your device management or patch-reporting tools. Until patched, treat social-engineering vectors as the main risk: caution users against interacting with untrusted pages, since the flaw requires user interaction but can yield sandbox-escaping code execution. Given the low EPSS and absence of a public PoC, there is no evidence of active targeting, but apply the update on normal high-priority patch cycles.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
masson the order of billions of users (Chrome has roughly 3+ billion active users worldwide) — Chrome's global installed base of billions of active users per public browser market-share data, with all users on builds earlier than 153.0.8010.36 exposed until they update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.