CVE-2026-87633
massUse-after-free in Google Chrome Views enables sandbox-escaping code execution
CVE-2026-87633 is a use-after-free memory corruption flaw (CWE-416) in the Views component of Google Chrome, the code that renders the browser's UI. A local attacker can trigger the flaw by getting a user to perform crafted UI interactions, which frees an object that is then reused by the browser. Successful exploitation allows arbitrary code execution outside the browser's sandbox, meaning an attacker who already has a foothold on the machine can escape Chrome's security containment and run code with broader privileges. All users running Google Chrome prior to 153.0.8010.36 are affected. There is currently no public proof-of-concept, no evidence of exploitation in the wild, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later on all endpoints, including managed fleets via enterprise update policies. Because exploitation requires a local attacker, prioritize patching shared, multi-user, and kiosk-style systems where untrusted users interact with the browser. No workarounds are documented, so verify installed versions in your inventory and confirm browsers auto-update once the fix rolls out.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.