ZeroHour

CVE-2026-87618

mass

Sandbox escape via incorrect reference resolution in Google Chrome on Windows

CVSS 3.1
8.3 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-87618 is an incorrect reference resolution flaw (CWE-706) in the Storage component of Google Chrome on Windows. It is triggered when a remote attacker, who has already compromised the browser's renderer process, gets the user to load a crafted HTML page. Successful exploitation allows the attacker to potentially execute arbitrary code outside the Chrome sandbox, effectively a sandbox escape; Chromium rates the flaw Low severity precisely because it requires that pre-existing renderer compromise. Anyone running Google Chrome on Windows prior to version 153.0.8010.36 is affected. No public proof-of-concept or in-the-wild exploitation is currently known, the flaw is not in CISA's KEV, and EPSS puts the 30-day exploitation probability at just 0.2%.

What to do: Update Google Chrome on Windows to 153.0.8010.36 or later; enterprises should verify patched browser versions via their update-management or endpoint inventories and keep managed-browser auto-update policies enabled. Treat this as a chain component: it matters most when combined with a renderer exploit, so patch promptly but prioritize higher-severity Chrome renderer bugs alongside it.

Affected
Google Chrome (Windows)all versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions to billions of Windows installations — Chrome is the dominant desktop browser with an estimated 3+ billion users worldwide and Windows is its largest platform, so plausibly affected Chrome-on-Windows installs number in the hundreds of millions or more, though the flaw only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Low)

Vendors
google
Products
chrome
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.