CVE-2026-87607
massUse-After-Free in Google Chrome on macOS Enables Code Execution Outside Sandbox
CVE-2026-87607 is a use-after-free vulnerability (CWE-416) in the Device component of Google Chrome on Mac, affecting macOS builds prior to 153.0.8010.36. A remote attacker can trigger the bug by luring a user to a crafted HTML page, consistent with the user-interaction requirement in the CVSS vector. Successful exploitation may allow the attacker to execute arbitrary code outside Chrome's sandbox — i.e., beyond the renderer's isolation — with high impact to confidentiality, integrity, and availability, reflected in the critical 9.6 CVSS score (network vector, no privileges required, changed scope). Only Chrome on Mac is named in the advisory; Windows and Linux builds and other Chromium-based browsers are not covered by this advisory and should be assessed separately. There is currently no evidence of exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days (17th percentile).
What to do: Mac users should update Chrome to 153.0.8010.36 or later (via chrome://settings/help or managed update policies/MDM) and relaunch the browser; until patched, exercise caution with untrusted links in Chrome on macOS. Administrators should verify fleet versions through Chrome Browser Cloud Management or MDM inventory reporting, and note that Windows/Linux builds and other Chromium-based browsers are not covered by this advisory.
| google chrome | Mac (macOS) builds prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.