CVE-2026-87609
massUse-after-free in Google Chrome for iOS allows code execution outside the sandbox
CVE-2026-87609 is a use-after-free vulnerability (CWE-416) in the Sharing component of Google Chrome on iOS, fixed in version 153.0.8010.36. A remote attacker can trigger the flaw via crafted network traffic, with user interaction required according to the CVSS vector (e.g., a user loading attacker-influenced content in the browser). Successful exploitation allows arbitrary code execution outside the Chrome sandbox, meaning attacker code runs with browser-process privileges on the device rather than being confined to the renderer. Only Chrome on iOS is named as affected in the advisory; Chrome on desktop and other platforms is not specified in this data. No public proof-of-concept, no CISA KEV listing, and an EPSS of 0.2% (15th percentile) indicate no known exploitation to date, and notably Google rates this Medium while the CVSS base score is 9.6.
What to do: Update Chrome for iOS to 153.0.8010.36 or later from the App Store, and verify browser versions on managed iOS fleets via MDM inventory. Because the flaw requires user interaction and no public exploit is known, no compensating mitigations are strictly required, but prioritize the update for users who browse untrusted content; continue monitoring Google's release notes for related iOS Chrome fixes.
| Google Chrome (iOS) | All versions prior to 153.0.8010.36 on iOS |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Sharing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.