CVE-2026-87588
massUse-after-free in Google Chrome Chromecast allows sandboxed code execution
CVE-2026-87588 is a use-after-free (CWE-416) in the Chromecast component of Google Chrome affecting all versions prior to 153.0.8010.36. A remote attacker triggers the flaw by persuading a user to open a crafted HTML page, with user interaction required as reflected in the CVSS vector (UI:R). Successful exploitation allows the attacker to execute arbitrary code inside the Chrome renderer sandbox, limiting impact to the sandboxed process; this explains the Chromium-assigned Medium severity even though the CVSS 3.1 base score is 8.8 (High). Any user running an affected Chrome build is exposed, which given Chrome's install base means effectively the entire Chrome user population. There is currently no known exploitation in the wild, no public proof of concept, no CISA KEV listing, and EPSS estimates only a 0.2% chance of exploitation within 30 days.
What to do: Upgrade Chrome to 153.0.8010.36 or later on all endpoints and verify the installed version at chrome://version; for managed fleets, push the update through your browser update management tooling. No workarounds are documented in the available data, so treat unpatched users as exposed and reinforce caution around unsolicited links, since exploitation requires the victim to visit a crafted page.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.