ZeroHour

CVE-2026-87613

mass

Sandbox Escape via Incorrect Reference Resolution in Google Chrome Extensions

CVSS 3.1
9.0 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-87613 is an incorrect reference resolution flaw (CWE-706) in the Extensions component of Google Chrome, fixed in version 153.0.8010.36. It can be triggered remotely via crafted network traffic; the CVSS vector shows no user interaction and no privileges are required, though high attack complexity (AC:H) makes reliable exploitation more difficult. If successfully exploited, an attacker could potentially execute arbitrary code outside the Chrome sandbox, meaning compromise beyond the browser process on the host machine. All Chrome users running a version prior to 153.0.8010.36 are affected. There is currently no known exploitation: EPSS puts the 30-day exploitation probability at only 0.2%, it is not in CISA KEV, and no public proof-of-concept is known; note that Chromium rated the underlying severity Medium despite the critical CVSS 9.0 score.

What to do: Update Google Chrome to 153.0.8010.36 or later at your normal patch cadence; verify the installed build via chrome://version or your endpoint/MDM inventory and confirm auto-updates are enabled. No workarounds are documented, and given the Medium Chromium severity rating, low EPSS, and absence of known exploitation, this can be treated as routine patching rather than an emergency.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
masson the order of billions of users (Chrome's global installed base; all users of builds before 153.0.8010.36) — Chrome is the world's most widely used browser with an installed base of roughly three billion users per public usage estimates, and because the flaw sits in the core Extensions component rather than a niche feature, essentially the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.