ZeroHour

CVE-2026-87607

mass

Use-After-Free in Google Chrome on macOS Enables Code Execution Outside Sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-87607 is a use-after-free vulnerability (CWE-416) in the Device component of Google Chrome on Mac, affecting macOS builds prior to 153.0.8010.36. A remote attacker can trigger the bug by luring a user to a crafted HTML page, consistent with the user-interaction requirement in the CVSS vector. Successful exploitation may allow the attacker to execute arbitrary code outside Chrome's sandbox — i.e., beyond the renderer's isolation — with high impact to confidentiality, integrity, and availability, reflected in the critical 9.6 CVSS score (network vector, no privileges required, changed scope). Only Chrome on Mac is named in the advisory; Windows and Linux builds and other Chromium-based browsers are not covered by this advisory and should be assessed separately. There is currently no evidence of exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days (17th percentile).

What to do: Mac users should update Chrome to 153.0.8010.36 or later (via chrome://settings/help or managed update policies/MDM) and relaunch the browser; until patched, exercise caution with untrusted links in Chrome on macOS. Administrators should verify fleet versions through Chrome Browser Cloud Management or MDM inventory reporting, and note that Windows/Linux builds and other Chromium-based browsers are not covered by this advisory.

Affected
google chromeMac (macOS) builds prior to 153.0.8010.36
Estimated exposure
mass≈100M+ users (Chrome-on-macOS population at disclosure; Chrome auto-update rapidly shrinks the still-vulnerable set) — Chrome is estimated to have roughly 3 billion users and is the dominant browser on macOS, a leading desktop platform, implying an order of magnitude of 10^8 Chrome-on-Mac users, though only installs below 153.0.8010.36 remain exposed once…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Device in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.