ZeroHour

CVE-2026-87616

mass

Improper Initialization in Google Chrome Views Enables Sandbox Escape on Windows

CVSS 3.1
8.3 high
EPSS
<1%p32
Published
()
Modified
AI analysis

CVE-2026-87616 is an improper initialization flaw (CWE-665) in the Views component of Google Chrome on Windows, fixed in Chrome 153.0.8010.36. To exploit it, an attacker must first compromise the Chrome renderer process, typically by getting a user to open a crafted HTML page, and then use social engineering to obtain additional user interaction. If successful, the attacker can execute arbitrary code outside the Chrome sandbox, effectively a sandbox escape that grants broader access to the host than a renderer compromise alone. Only Chrome on Windows prior to 153.0.8010.36 is affected by this advisory. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.

What to do: Update Chrome on Windows to version 153.0.8010.36 or later via chrome://settings/help. Because exploitation requires an already-compromised renderer plus user interaction, standard patch cadence is defensible, but prioritize Windows endpoints whose users browse untrusted websites. No workarounds are documented beyond prompt patching.

Affected
Google ChromeChrome on Windows prior to 153.0.8010.36
Estimated exposure
mass~1-2 billion Chrome-on-Windows users/installations (order of magnitude: ~10^9) — Chrome is estimated at over 3 billion users worldwide and Windows accounts for the majority of desktop Chrome usage, so the affected Windows population prior to the 153.0.8010.36 fix is plausibly on the order of a billion or more…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-665
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.