ZeroHour

CVE-2026-87633

mass

Use-after-free in Google Chrome Views enables sandbox-escaping code execution

CVSS 3.1
8.6 high
EPSS
<1%p5
Published
()
Modified
AI analysis

CVE-2026-87633 is a use-after-free memory corruption flaw (CWE-416) in the Views component of Google Chrome, the code that renders the browser's UI. A local attacker can trigger the flaw by getting a user to perform crafted UI interactions, which frees an object that is then reused by the browser. Successful exploitation allows arbitrary code execution outside the browser's sandbox, meaning an attacker who already has a foothold on the machine can escape Chrome's security containment and run code with broader privileges. All users running Google Chrome prior to 153.0.8010.36 are affected. There is currently no public proof-of-concept, no evidence of exploitation in the wild, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later on all endpoints, including managed fleets via enterprise update policies. Because exploitation requires a local attacker, prioritize patching shared, multi-user, and kiosk-style systems where untrusted users interact with the browser. No workarounds are documented, so verify installed versions in your inventory and confirm browsers auto-update once the fix rolls out.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3+ billion Chrome installations/users worldwide — Chrome holds roughly 60-65% of global browser usage share across billions of desktop and mobile devices, so nearly every Chrome deployment older than 153.0.8010.36 is affected, though exploitation additionally requires local attacker…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.