ZeroHour

CVE-2026-87630

mass

Integer Overflow in Google Chrome WebRTC Enables Sandboxed Memory Disclosure

CVSS 3.1
4.3 medium
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-87630 is an integer-overflow flaw (CWE-190) in the WebRTC component of Google Chrome, rated Medium (CVSS 3.1: 4.3) at Chromium security severity Medium, and it is fixed in Chrome 153.0.8010.36 — one of 230 security fixes in that release, per related coverage. A remote attacker triggers it by luring a user (user interaction is required) to open a crafted HTML page, causing the integer overflow in WebRTC processing. Successful exploitation lets the attacker read memory inside Chrome's sandbox — an information-disclosure condition (low confidentiality impact, no integrity or availability impact) that could leak in-sandbox data or serve as a link in a broader exploit chain. Anyone running Google Chrome on a version before 153.0.8010.36 is affected; the advisory names only Chrome, and given Chrome's install base the exposed population is on the order of billions of users. No public proof-of-concept is known and EPSS puts 30-day exploitation probability at just 0.2% (15th percentile); the Chrome 153 release was reported alongside an unspecified zero-day exploited in the wild, but the provided data does not confirm that this specific CVE is that zero-day.

What to do: Update Google Chrome to 153.0.8010.36 or later (check chrome://settings/help) and enforce the version through managed browser update policies, confirming no managed endpoints remain on older builds. Because exploitation requires a user to load a crafted page, treat unsolicited links cautiously until patched, and note that in-sandbox memory-disclosure bugs are commonly chained with sandbox-escape flaws, so prompt patching matters.

Affected
Google Chrome (WebRTC component)all versions prior to 153.0.8010.36
Estimated exposure
massroughly 3 billion+ users (Chrome's global install base; about two-thirds of browser market share) — Chrome is the world's dominant desktop and mobile browser with a multi-billion install base, and any web page an attacker can induce a user to open can invoke WebRTC, so effectively the entire pre-153.0.8010.36 user base was exposed at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

Google Chrome 153 Released With 230 Security Fixes and Zero-Day Exploited in the Wild

Google released Chrome 153 with 230 security fixes, patching CVE-2026-87491, a V8 out-of-bounds write zero-day actively exploited in the wild.

Google shipped Chrome 153 (153.0.8010.36/.37) for Windows, macOS, and Linux with 230 security fixes, including CVE-2026-87491, a medium-severity V8 out-of-bounds write being exploited in the wild. The release also fixes five critical vulnerabilities: four in WebGL (two use-after-frees, an out-of-bounds write, a buffer overflow) and one use-after-free in Cast. High-severity V8 use-after-free and type-confusion defects are among the fixes, and Google has restricted technical details until most users are patched. Administrators should verify deployed versions on managed endpoints, as Chrome-derived browsers may follow different patch schedules.

GBHackers · 6d agoExploit / PoC in the wildCVE-2026-87491CVE-2026-87464CVE-2026-87488+19 CVEs