ZeroHour

CVE-2026-87617

mass

Use-after-free in Google Chrome DevTools enables sandboxed code execution

CVSS 3.1
8.8 high
EPSS
<1%p30
Published
()
Modified
AI analysis

CVE-2026-87617 is a use-after-free memory-safety flaw (CWE-416) in the DevTools component of Google Chrome, fixed in Chrome 153.0.8010.36. Exploitation requires social engineering: a remote attacker must lure a user into opening or interacting with a crafted HTML page, after which the flaw can be triggered to run arbitrary code — though only within the browser's sandbox, limiting the attacker's access to the underlying system. Google rated it Low on the Chromium security severity scale, consistent with the sandbox containment, while the CVSS 3.1 base score of 8.8 reflects worst-case impact without accounting for that limitation. Any Chrome installation on a version earlier than 153.0.8010.36 is affected. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days.

What to do: Update Chrome to 153.0.8010.36 or later via chrome://settings/help and verify that auto-updates are enabled on both managed and personal endpoints. No workarounds are documented; as an interim precaution, caution users against interacting with unsolicited web pages that prompt unusual actions, since user interaction is required for exploitation. Inventory tools should flag any Chrome installs below 153.0.8010.36.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's estimated global install base) — Chrome is the world's most widely used desktop browser with an estimated multi-billion-user install base, and every build before 153.0.8010.36 is in the affected range.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.