CVE-2026-87617
massUse-after-free in Google Chrome DevTools enables sandboxed code execution
CVE-2026-87617 is a use-after-free memory-safety flaw (CWE-416) in the DevTools component of Google Chrome, fixed in Chrome 153.0.8010.36. Exploitation requires social engineering: a remote attacker must lure a user into opening or interacting with a crafted HTML page, after which the flaw can be triggered to run arbitrary code — though only within the browser's sandbox, limiting the attacker's access to the underlying system. Google rated it Low on the Chromium security severity scale, consistent with the sandbox containment, while the CVSS 3.1 base score of 8.8 reflects worst-case impact without accounting for that limitation. Any Chrome installation on a version earlier than 153.0.8010.36 is affected. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days.
What to do: Update Chrome to 153.0.8010.36 or later via chrome://settings/help and verify that auto-updates are enabled on both managed and personal endpoints. No workarounds are documented; as an interim precaution, caution users against interacting with unsolicited web pages that prompt unusual actions, since user interaction is required for exploitation. Inventory tools should flag any Chrome installs below 153.0.8010.36.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.