ZeroHour

CVE-2026-87588

mass

Use-after-free in Google Chrome Chromecast allows sandboxed code execution

CVSS 3.1
8.8 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-87588 is a use-after-free (CWE-416) in the Chromecast component of Google Chrome affecting all versions prior to 153.0.8010.36. A remote attacker triggers the flaw by persuading a user to open a crafted HTML page, with user interaction required as reflected in the CVSS vector (UI:R). Successful exploitation allows the attacker to execute arbitrary code inside the Chrome renderer sandbox, limiting impact to the sandboxed process; this explains the Chromium-assigned Medium severity even though the CVSS 3.1 base score is 8.8 (High). Any user running an affected Chrome build is exposed, which given Chrome's install base means effectively the entire Chrome user population. There is currently no known exploitation in the wild, no public proof of concept, no CISA KEV listing, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

What to do: Upgrade Chrome to 153.0.8010.36 or later on all endpoints and verify the installed version at chrome://version; for managed fleets, push the update through your browser update management tooling. No workarounds are documented in the available data, so treat unpatched users as exposed and reinforce caution around unsolicited links, since exploitation requires the victim to visit a crafted page.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3 billion users (Chrome's global install base) — Chrome is the world's dominant browser with roughly three billion users and about two-thirds desktop market share, so essentially all deployments running builds before 153.0.8010.36 are potentially affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Chromecast in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.