ZeroHour

CVE-2026-87621

mass

Out-of-Bounds Write in ANGLE in Google Chrome on Windows Allows Sandbox Escape

CVSS 3.1
9.6 critical
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-87621 is an out-of-bounds write (CWE-787) in ANGLE, the graphics translation layer Google Chrome uses on Windows for WebGL and GPU rendering. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, requiring no privileges (CVSS 3.1: 9.6, AV:N/AC:L/PR:N/UI:R/S:C). Successful exploitation potentially allows arbitrary code execution outside the browser's sandbox, meaning the attacker escapes the renderer and can affect the underlying Windows system rather than just the browser tab. Only Chrome on Windows is named as affected; the flaw is fixed in Chrome 153.0.8010.36, one of 230 security fixes in the Chrome 153 release. Exploitation signals are mixed: EPSS is low (0.2% probability in 30 days, percentile 12), the bug is not in CISA KEV and no public PoC is known, but related reporting on the Chrome 153 release states that a zero-day was exploited in the wild.

What to do: Upgrade Google Chrome on Windows to 153.0.8010.36 or later immediately (via Settings > About Chrome or your enterprise update channel) and verify fleet versions through update telemetry. Until patched, avoid untrusted websites and consider disabling WebGL on high-risk Windows endpoints, since ANGLE translates WebGL calls. This release also contains 230 security fixes, so prioritize broad and rapid deployment.

Affected
Google ChromeOn Windows, all versions prior to 153.0.8010.36
Estimated exposure
mass≈1 billion+ users (Chrome on Windows on versions prior to 153.0.8010.36) — Chrome has roughly 3-4 billion users with about 65% browser share and Windows runs on roughly 70% of desktop systems, so Chrome-on-Windows installations plausibly exceed one billion, with anyone not yet updated to 153.0.8010.36 exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs