ZeroHour

CVE-2026-87612

mass

Type Confusion in Google Chrome's V8 Engine Enables In-Sandbox Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p24
Published
()
Modified
AI analysis

Google Chrome versions prior to 153.0.8010.36 contain a type confusion flaw in the V8 JavaScript engine (CWE-843), rated High severity with a CVSS 3.1 score of 8.8. A remote attacker can trigger it by luring a user to a crafted HTML page, causing V8 to mishandle object types and corrupt memory during script execution. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, which limits the immediate impact to the sandbox's privileges unless the attacker chains it with a separate sandbox escape. Anyone running an affected Chrome build is exposed, which in practice spans nearly the browser's entire multi-billion-user install base. Related coverage of the Chrome 153 release (230 security fixes) reports a zero-day exploited in the wild, while the CVE record itself lists no public PoC, no CISA KEV entry, and a modest 0.2% EPSS probability of exploitation in the next 30 days.

What to do: Update Chrome to 153.0.8010.36 or later immediately and confirm the patched version via chrome://settings/help; enterprise administrators should push the update through their browser management tooling and force relaunches so the fix takes effect. Because exploitation is reported in the wild in connection with the Chrome 153 release, treat this as a priority patch, and monitor for follow-on sandbox-escape exploits since this flaw alone grants only sandboxed code execution.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global install base; every build before 153.0.8010.36 is vulnerable) — Chrome is the world's most widely used desktop browser with a global user base measured in billions, and all installations running versions earlier than 153.0.8010.36 are affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 7d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs1