CVE-2026-87601
massRace Condition in Google Chrome V8 Enables Sandbox-Confined Code Execution
CVE-2026-87601 is a race condition (CWE-362) in the V8 JavaScript engine of Google Chrome. A remote attacker can trigger the flaw by luring a user to a specially crafted HTML page, where a timing window in V8 allows execution of arbitrary code. The attacker gains code execution strictly inside Chrome's sandbox, with no sandbox escape, limiting the real-world impact; Google rated the issue Low while the CVSS 3.1 base score is 7.5 (high), reflecting high attack complexity and required user interaction. All Chrome users running versions prior to 153.0.8010.36 are affected. There is no known public proof-of-concept, no evidence of exploitation in the wild, and the flaw is not in CISA KEV; EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Update Chrome to 153.0.8010.36 or later on all platforms, verifying via chrome://settings/help that auto-update has completed. Until patched, limit exposure to untrusted web content; the sandbox confinement reduces the impact if exploitation succeeds. Enterprise administrators should confirm deployed browser versions through endpoint management tooling.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Race condition in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.