ZeroHour

CVE-2026-87586

PoC mass

Out-of-bounds read in Google Chrome's ANGLE graphics layer (CVE-2026-87586)

CVSS 3.1
4.3 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-87586 is an out-of-bounds read (CWE-125) in ANGLE, the graphics translation layer used by Google Chrome, affecting versions prior to 153.0.8010.36. It is triggered remotely via a crafted HTML page: an attacker who gets a user to open malicious web content can cause ANGLE to read memory beyond its intended bounds. A successful exploit allows the attacker to read memory outside the Chrome sandbox, which can disclose sensitive process memory, though the flaw does not by itself enable code execution. All users running Chrome versions before 153.0.8010.36 are affected. There is no CISA KEV listing, EPSS is low (0.2% probability of exploitation in 30 days, 7th percentile), and one public reference exists on the Chromium issue tracker, so no widespread in-the-wild exploitation is currently known.

What to do: Update Google Chrome to 153.0.8010.36 or later and verify the deployed version across managed endpoints (e.g., via chrome://settings/help or enterprise patch reporting). Until patched, limit exposure to untrusted web content on high-value systems, since the flaw is reachable through a crafted HTML page. Given the Medium severity, low EPSS, and no KEV entry, standard patch-cadence handling is reasonable, but browser updates should not be deferred long because the browser is the primary attack surface here.

Affected
Google Chromeall versions prior to 153.0.8010.36 (fixed in 153.0.8010.36)
Estimated exposure
masson the order of billions of Chrome installations (Chrome is the dominant desktop browser with roughly two-thirds of browser market share); nearly all unpatched… — Chrome's installed base is measured in the billions of users, and every installation on a version before 153.0.8010.36 was vulnerable to this flaw until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.