CVE-2026-87613
massSandbox Escape via Incorrect Reference Resolution in Google Chrome Extensions
CVE-2026-87613 is an incorrect reference resolution flaw (CWE-706) in the Extensions component of Google Chrome, fixed in version 153.0.8010.36. It can be triggered remotely via crafted network traffic; the CVSS vector shows no user interaction and no privileges are required, though high attack complexity (AC:H) makes reliable exploitation more difficult. If successfully exploited, an attacker could potentially execute arbitrary code outside the Chrome sandbox, meaning compromise beyond the browser process on the host machine. All Chrome users running a version prior to 153.0.8010.36 are affected. There is currently no known exploitation: EPSS puts the 30-day exploitation probability at only 0.2%, it is not in CISA KEV, and no public proof-of-concept is known; note that Chromium rated the underlying severity Medium despite the critical CVSS 9.0 score.
What to do: Update Google Chrome to 153.0.8010.36 or later at your normal patch cadence; verify the installed build via chrome://version or your endpoint/MDM inventory and confirm auto-updates are enabled. No workarounds are documented, and given the Medium Chromium severity rating, low EPSS, and absence of known exploitation, this can be treated as routine patching rather than an emergency.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect reference resolution in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-706
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.