ZeroHour

CVE-2026-87609

mass

Use-after-free in Google Chrome for iOS allows code execution outside the sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-87609 is a use-after-free vulnerability (CWE-416) in the Sharing component of Google Chrome on iOS, fixed in version 153.0.8010.36. A remote attacker can trigger the flaw via crafted network traffic, with user interaction required according to the CVSS vector (e.g., a user loading attacker-influenced content in the browser). Successful exploitation allows arbitrary code execution outside the Chrome sandbox, meaning attacker code runs with browser-process privileges on the device rather than being confined to the renderer. Only Chrome on iOS is named as affected in the advisory; Chrome on desktop and other platforms is not specified in this data. No public proof-of-concept, no CISA KEV listing, and an EPSS of 0.2% (15th percentile) indicate no known exploitation to date, and notably Google rates this Medium while the CVSS base score is 9.6.

What to do: Update Chrome for iOS to 153.0.8010.36 or later from the App Store, and verify browser versions on managed iOS fleets via MDM inventory. Because the flaw requires user interaction and no public exploit is known, no compensating mitigations are strictly required, but prioritize the update for users who browse untrusted content; continue monitoring Google's release notes for related iOS Chrome fixes.

Affected
Google Chrome (iOS)All versions prior to 153.0.8010.36 on iOS
Estimated exposure
mass≈hundreds of millions of users (Chrome for iOS install base; overall Chrome user base exceeds 3 billion) — Chrome is the world's most widely used browser with billions of users, and the iOS build has been installed on the order of hundreds of millions of Apple devices, though the exact population of vulnerable pre-153.0.8010.36 iOS installs is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.