ZeroHour

CVE-2026-87587

mass

Use-after-free in Google Chrome's V8 engine allows sandboxed code execution

CVSS 3.1
8.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-87587 is a use-after-free memory-safety vulnerability (CWE-416) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 153.0.8010.36 as part of a release carrying roughly 230 security fixes. An attacker triggers it by getting a user to open a crafted HTML page, which causes the V8 engine to reference freed memory. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox (CVSS 3.1: 8.8 High, with high impact to confidentiality, integrity, and availability), though the flaw as described does not by itself escape the sandbox. All Chrome users running versions prior to 153.0.8010.36 are affected. No public proof-of-concept is known, the flaw is not yet in CISA KEV, and EPSS is currently low (0.2% over 30 days), but related reporting on the Chrome 153 release states a zero-day was exploited in the wild, so active exploitation cannot be ruled out.

What to do: Update Chrome to 153.0.8010.36 or later immediately and verify build versions across your fleet (chrome://settings/help, or enforce via enterprise browser update policies). Until patched, have users avoid untrusted web content and prioritize rollout to high-risk and internet-exposed users, given reporting of an in-the-wild zero-day accompanying this release.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈2-3 billion Chrome users (Chrome is the world's most widely used browser; the vulnerable set shrinks rapidly as auto-update rolls out 153.0.8010.36) — Chrome holds roughly two-thirds of global browser market share, implying an install base in the billions, with actual exposure limited to users not yet auto-updated to 153.0.8010.36.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs