ZeroHour

CVE-2026-87625

mass

Use-After-Free in Google Chrome's V8 Engine Allows Sandboxed Code Execution

CVSS 3.1
8.8 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-87625 is a use-after-free memory-safety flaw (CWE-416) in the V8 JavaScript engine of Google Chrome versions prior to 153.0.8010.36. A remote attacker triggers it by using social engineering to lure a user into interacting with a crafted Chrome extension, which exercises the flawed V8 code path and corrupts freed memory. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, with high confidentiality, integrity, and availability impact on the affected process; the CVSS 3.1 rating of 8.8 (High) reflects the need for user interaction rather than a pre-authentication flaw. Every user or organization running an affected Chrome build is exposed until updated. Chrome 153 shipped with 230 security fixes and related reporting indicates a zero-day was exploited in the wild at release, though no public proof-of-concept is cataloged for this specific CVE and EPSS remains low (0.2%).

What to do: Update Google Chrome to 153.0.8010.36 or later via the built-in updater (Settings > About Chrome) or enterprise update policies, and verify fleet versions afterward. Until patched, caution users against installing or interacting with untrusted Chrome extensions, since exploitation requires user interaction. Note that while EPSS is low (0.2%), in-the-wild zero-day exploitation was reported alongside the Chrome 153 release.

Affected
google chromeprior to 153.0.8010.36
Estimated exposure
massbillions of users (Chrome's global install base on pre-153.0.8010.36 builds) — Chrome holds roughly two-thirds of desktop browser usage share, implying a multi-billion install base, and every build older than 153.0.8010.36 carries the vulnerable V8 code until the auto-update is applied.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs