CVE-2026-87616
massImproper Initialization in Google Chrome Views Enables Sandbox Escape on Windows
CVE-2026-87616 is an improper initialization flaw (CWE-665) in the Views component of Google Chrome on Windows, fixed in Chrome 153.0.8010.36. To exploit it, an attacker must first compromise the Chrome renderer process, typically by getting a user to open a crafted HTML page, and then use social engineering to obtain additional user interaction. If successful, the attacker can execute arbitrary code outside the Chrome sandbox, effectively a sandbox escape that grants broader access to the host than a renderer compromise alone. Only Chrome on Windows prior to 153.0.8010.36 is affected by this advisory. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.
What to do: Update Chrome on Windows to version 153.0.8010.36 or later via chrome://settings/help. Because exploitation requires an already-compromised renderer plus user interaction, standard patch cadence is defensible, but prioritize Windows endpoints whose users browse untrusted websites. No workarounds are documented beyond prompt patching.
| Google Chrome | Chrome on Windows prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-665
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.