AI analysis
CVE-2026-87621 is an out-of-bounds write (CWE-787) in ANGLE, the graphics translation layer Google Chrome uses on Windows for WebGL and GPU rendering. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, requiring no privileges (CVSS 3.1: 9.6, AV:N/AC:L/PR:N/UI:R/S:C). Successful exploitation potentially allows arbitrary code execution outside the browser's sandbox, meaning the attacker escapes the renderer and can affect the underlying Windows system rather than just the browser tab. Only Chrome on Windows is named as affected; the flaw is fixed in Chrome 153.0.8010.36, one of 230 security fixes in the Chrome 153 release. Exploitation signals are mixed: EPSS is low (0.2% probability in 30 days, percentile 12), the bug is not in CISA KEV and no public PoC is known, but related reporting on the Chrome 153 release states that a zero-day was exploited in the wild.
What to do: Upgrade Google Chrome on Windows to 153.0.8010.36 or later immediately (via Settings > About Chrome or your enterprise update channel) and verify fleet versions through update telemetry. Until patched, avoid untrusted websites and consider disabling WebGL on high-risk Windows endpoints, since ANGLE translates WebGL calls. This release also contains 230 security fixes, so prioritize broad and rapid deployment.
Affected
| Google Chrome | On Windows, all versions prior to 153.0.8010.36 |
Estimated exposure
mass≈1 billion+ users (Chrome on Windows on versions prior to 153.0.8010.36) — Chrome has roughly 3-4 billion users with about 65% browser share and Windows runs on roughly 70% of desktop systems, so Chrome-on-Windows installations plausibly exceed one billion, with anyone not yet updated to 153.0.8010.36 exposed.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.