ZeroHour

CVE-2026-87585

mass

Double-Free in Google Chrome PDFium (Windows) Enables Sandbox-Confined Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-87585 is a double-free memory-corruption flaw (CWE-415) in the PDFium PDF rendering engine of Google Chrome on Windows. It is triggered when the browser opens a maliciously crafted PDF file, and a successful exploit allows a remote attacker to potentially execute arbitrary code inside Chrome's sandbox, limiting but not eliminating attacker access per the High CVSS impact ratings. All Chrome users on Windows running versions prior to 153.0.8010.36 are affected. No public proof-of-concept is known, the bug is not in CISA's KEV, and EPSS estimates only a ~0.2% probability of exploitation within 30 days. The fix is included in Chrome 153.0.8010.36 for Windows, a release with 230 security fixes that also addresses a separately reported zero-day exploited in the wild, though the headlines do not confirm whether that zero-day is this specific flaw.

What to do: Update Google Chrome on Windows to 153.0.8010.36 or later; verify the installed version via chrome://settings/help or chrome://version. As an interim mitigation, avoid opening PDFs from untrusted sources in Chrome or use a separate PDF reader until patched. Admins should push the updated build through their browser-management channels and note that Chrome 155 includes many other fixes, including a separately reported in-the-wild zero-day.

Affected
Google Chrome (PDFium) on WindowsAll versions prior to 153.0.8010.36 on Windows
Estimated exposure
masswell over 1 billion Chrome-on-Windows users (Chrome has a global desktop install base in the billions, with Windows accounting for the large majority of… — Chrome is the world's dominant desktop browser with a multi-billion-user install base, and the Windows-only scoping still leaves the affected population at the billion-user order of magnitude; the exact figure is an estimate and unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-415
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs

Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

Google shipped Chrome 153 with 230 fixes, including CVE-2026-87491, a V8 out-of-bounds write zero-day exploited in the wild.

Chrome 153 (153.0.8010.36/.37) rolls out to Windows, Mac, and Linux with 230 security fixes, among the largest patch batches in recent Chrome history. The headline flaw is CVE-2026-87491, a Medium-severity out-of-bounds write in the V8 JavaScript and WebAssembly engine that Google confirmed is exploited in the wild; it was reported by Jihyeon Jeong of Compsec Lab at Seoul National University for a $2,500 bounty. The release also closes five Critical-rated flaws, including CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527, and CVE-2026-87628, mostly use-after-free and out-of-bounds write bugs in WebGL and Cast, plus 43 High-severity issues across ANGLE, PDFium, V8, DevTools, and Payments. Several bugs were surfaced with AI-assisted discovery tools, including OpenAI's Codex Security team, and top bounties reached $5,000 for CVE-2026-87504.