AI analysis
CVE-2026-87625 is a use-after-free memory-safety flaw (CWE-416) in the V8 JavaScript engine of Google Chrome versions prior to 153.0.8010.36. A remote attacker triggers it by using social engineering to lure a user into interacting with a crafted Chrome extension, which exercises the flawed V8 code path and corrupts freed memory. Successful exploitation lets the attacker execute arbitrary code inside the browser's sandbox, with high confidentiality, integrity, and availability impact on the affected process; the CVSS 3.1 rating of 8.8 (High) reflects the need for user interaction rather than a pre-authentication flaw. Every user or organization running an affected Chrome build is exposed until updated. Chrome 153 shipped with 230 security fixes and related reporting indicates a zero-day was exploited in the wild at release, though no public proof-of-concept is cataloged for this specific CVE and EPSS remains low (0.2%).
What to do: Update Google Chrome to 153.0.8010.36 or later via the built-in updater (Settings > About Chrome) or enterprise update policies, and verify fleet versions afterward. Until patched, caution users against installing or interacting with untrusted Chrome extensions, since exploitation requires user interaction. Note that while EPSS is low (0.2%), in-the-wild zero-day exploitation was reported alongside the Chrome 153 release.
Affected
| google chrome | prior to 153.0.8010.36 |
Estimated exposure
massbillions of users (Chrome's global install base on pre-153.0.8010.36 builds) — Chrome holds roughly two-thirds of desktop browser usage share, implying a multi-billion install base, and every build older than 153.0.8010.36 carries the vulnerable V8 code until the auto-update is applied.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.