AI analysis
CVE-2026-87587 is a use-after-free memory-safety vulnerability (CWE-416) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 153.0.8010.36 as part of a release carrying roughly 230 security fixes. An attacker triggers it by getting a user to open a crafted HTML page, which causes the V8 engine to reference freed memory. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox (CVSS 3.1: 8.8 High, with high impact to confidentiality, integrity, and availability), though the flaw as described does not by itself escape the sandbox. All Chrome users running versions prior to 153.0.8010.36 are affected. No public proof-of-concept is known, the flaw is not yet in CISA KEV, and EPSS is currently low (0.2% over 30 days), but related reporting on the Chrome 153 release states a zero-day was exploited in the wild, so active exploitation cannot be ruled out.
What to do: Update Chrome to 153.0.8010.36 or later immediately and verify build versions across your fleet (chrome://settings/help, or enforce via enterprise browser update policies). Until patched, have users avoid untrusted web content and prioritize rollout to high-risk and internet-exposed users, given reporting of an in-the-wild zero-day accompanying this release.
Affected
| google chrome | all versions prior to 153.0.8010.36 |
Estimated exposure
mass≈2-3 billion Chrome users (Chrome is the world's most widely used browser; the vulnerable set shrinks rapidly as auto-update rolls out 153.0.8010.36) — Chrome holds roughly two-thirds of global browser market share, implying an install base in the billions, with actual exposure limited to users not yet auto-updated to 153.0.8010.36.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.